Skip to main content
ChangeGuard AI includes model-assisted analysis of your cluster’s security posture — the backend owns the facts and the numbers; the model writes the language. By default this runs server-side on Amazon Bedrock using Anthropic’s Claude — there is nothing to install and no GPU required. For self-hosted or air-gapped environments, you can route inference through NVIDIA NIM instead.

Inference backends

What AI Analyzes

  • Risk explanations — why a CVE or finding matters
  • Remediation guidance — specific commands to fix issues
  • Compliance mapping — which controls a finding affects
  • Attack path narrative — privilege escalation chains in plain English

Configuration

AI analysis works out of the box on Amazon Bedrock — no configuration required. Add an ai block to your ChangeGuardAgent resource only if you want to route inference through NVIDIA NIM instead.
See NVIDIA NIM Integration for detailed setup.