Bedrock Data brings enterprise data context to NVIDIA OpenShell, evaluating each agent action against data policy and returning the decision OpenShell enforces at runtime
SAN MATEO, Calif.--(BUSINESS WIRE)--Bedrock Data, the platform provider for data and AI security and governance, and data security posture management (DSPM), today announced it has extended Agent DLP™, its runtime data loss prevention for AI agents, to NVIDIA OpenShell, the open source agent runtime that is part of the NVIDIA Open Safety Platform. NVIDIA OpenShell gives autonomous agents a secure environment to run in with strong isolation and a zero-trust architecture where nothing is permitted by default. This integration offers an additional policy evaluation layer where Bedrock Data evaluates a request payload once the request is authorized by OpenShell. Bedrock Data’s authorization layer evaluates the payload in the request against an enterprise’s data policies. The integration is available today to Bedrock Data customers.


“The identities enterprises bind to agents are usually more permissive than the task requires, so an agent pursuing a goal can access data nobody meant it to have, combine sources into toxic data combinations and share sensitive data to finish the job,” said Pranava Adduri, CTO and co-founder of Bedrock Data. “NVIDIA OpenShell gives enterprises the place to enforce a decision on each action an agent takes. Bedrock Data evaluates that action based on what the data in the request is and what company policy allows, and returns the decision. Together, NVIDIA OpenShell and Bedrock Data let enterprises scale their use of agents while company policy controls what agents are allowed to do with sensitive enterprise data.”
Permissions govern which resources and operations an agent may use, but they are not data-aware: within a permitted operation, they cannot tell sensitive data from harmless data. An agent can hold exactly the permissions its job requires and still create exposure: to complete an interim computation, it writes sensitive data to a shared scratch table its job requires it to use. Every permission was correctly scoped, but none could express which data may be written there; as a result, data that was tightly restricted is now readable by everyone with access to the table. A sandbox can stop the write, but deciding when to stop it requires knowing what the data is, where it came from, what it has been combined with and where it can go. Bedrock Data evaluates an agent's action against data policy and tells OpenShell when the data involved is or isn't cleared for the destination; OpenShell can block the action accordingly.
Bedrock Data Supplies the Data Context and the Decision, NVIDIA OpenShell Enforces the Policy for Agents
NVIDIA OpenShell gives each agent a sandbox to do their work, with kernel-level enforcement over their processes, filesystem and outgoing connections, and checks outbound actions against policy before they take effect. OpenShell’s Supervisor Middleware is the extension point Bedrock Data leverages for the additional data-based policy enforcement.
Bedrock Data evaluates each request against the enterprise's data policies, which are defined on Bedrock’s Metadata Lake: an enterprise knowledge graph that connects what data is, where it lives, where it came from, who can access it and how it is used. Bedrock Data builds the graph by discovering and classifying data in place across cloud, SaaS, AI and on-premises environments at petabyte scale, and keeps it current as data and access change. The decision is based on what the graph knows about the data in the request and where it is going, not on patterns in the payload, so a restriction travels with the data as it passes from one agent to another.
Bedrock Data performs three functions for OpenShell:
- At runtime, it evaluates each action and returns the decision OpenShell enforces. A write of sensitive data to a shared scratch table is stopped, while the same write to a table restricted to that data's approved audience proceeds.
- At design time, it shows security teams an agent's blast radius, such as what data its permissions can access, what that data combines into and where policy would be violated.
- It makes OpenShell's enforcement data-aware. As data and access change, the decisions OpenShell enforces change with them, without anyone rewriting a rule.
“Enterprises are running fleets of long-horizon agents that fan out into thousands of sub-agents, and permissions alone can't tell them which data can safely move where,” said Ali Golshan, Senior Director of Product, NVIDIA. “NVIDIA OpenShell enforces policy on every agent action at the sandbox boundary. Bedrock Data's supervisor middleware makes that decision data-aware, so the runtime that isolates the agent also knows what the agent is carrying.”
With the integration, enterprises get:
- Sensitive data that stays protected even when permissions allow the action. Restrictions follow the data across tables, tools and handoffs between agents, so an action permissions permit is still stopped when the data in it may not go where it is headed: a customer record written to a shared scratch table, or proprietary code pasted into a public GitHub issue.
- Agents take on more work with less sign-off. Clear cases proceed without a person in the loop. Only actions policy cannot resolve reach the designated approver, and a blocked agent gets a path to revise rather than a dead end.
- One control point for every tool and every agent. Policy applies at the OpenShell sandbox boundary however an agent acts, through an MCP tool, a command-line invocation or code it writes itself, and the same data policies govern every agent that runs there.
Availability
Bedrock Data Agent DLP for NVIDIA OpenShell is available today to Bedrock Data customers as an OpenShell supervisor middleware service. Teams can run it in observe-only mode first, recording the decisions Bedrock Data returns without enforcing them, and turn on enforcement when they are ready. See also technical details on the Bedrock Data blog.
Additional Resources
- Read the Bedrock Data blog to learn more about Bedrock Data’s integration with NVIDIA OpenShell
- Learn more about NVIDIA OpenShell and the NVIDIA Open Safety Platform
- Learn more about Bedrock Data Agent DLP
- Request a Bedrock Data platform demo
- Follow Bedrock Data on LinkedIn, X and Bluesky
About Bedrock Data
Bedrock Data is a data security and AI governance platform built on an enterprise knowledge graph of the company's data: what it is, where it lives, where it came from, who can access it and how it is used. Bedrock Data builds and maintains that graph, its patented Metadata Lake, by discovering and classifying data in place across cloud, SaaS, AI and on-premises environments at petabyte scale, without moving data outside customer boundaries. Its open, API-first design delivers those facts to the tools already in the enterprise stack and makes them the basis for policy enforcement, AI governance and automated remediation. Security, data, infrastructure and AI leaders in technology, finance, healthcare and biotech rely on Bedrock Data to secure their data and accelerate AI without increasing risk. Learn more at bedrockdata.ai.
Contacts
Pam Njissang
Bhava Communications for Bedrock Data
bedrockdata@bhavacom.com





