hncb-fusion-deid-demo

All-AWS demo of the HNCB use case: a reversible PII de-identification round trip through Axway Amplify AI Gateway (Fusion), with the reasoning done by an Amazon Bedrock AgentCore agent. The advisor types a query containing a real name; the cloud only ever sees a token; the real identity is restored on-prem before the answer is shown.

Status: unrun scaffold. This was authored, not executed. Review everything, pin dependency versions, and expect to adjust AgentCore/Fusion specifics to the current CLI/console. Demo-grade, not production-grade.

What it demonstrates

Raw PII (a Chinese name + a Taiwan ROC ID) is detected on ingress, replaced with a random, format-safe token, and only the tokenized prompt goes to the cloud agent. The agent calls a tool back "on-prem" with the token, gets a de-identified evidence package, and writes talking points. Fusion restores the identity on the way out. The money shot: show the Bedrock request / AgentCore trace live — the cloud only ever saw CUST_000123, never 王小明.

Trust zones are logical

Everything is one AWS account. The "on-prem" zone is a set of tag-labelled resources (Zone = on-prem-VPC-A) standing in for HNCB's branch data centre. This demo proves behaviour and data-flow, not physical data residency — say so on camera: "in production this zone is the branch DC; here a VPC stands in for it."

Component → service map (their 8 steps)

Step Component Service in this repo
1, 8 Advisor UI ui/index.html on S3+CloudFront (or local)
2, 3-route, 8 Fusion AI Gateway (the product) ECS Fargate — terraform/ecs.tf, config in fusion/POLICY_SETUP.md
2 PII detector (typed findings, not redaction) Presidio on Fargate — presidio/
2, 4, 8 Token vault (reversible map) DynamoDB — terraform/main.tf
3, 7 Cloud agent + model AgentCore Runtime + Bedrock — agent/
4 Tool bridge (Lambda → MCP tool) AgentCore Gateway — scripts/agentcore_setup.sh
4-6 On-prem RAG tool + data Lambda + DynamoDB — lambda_rag/, seed/
all Observability AgentCore Observability + CloudWatch

Repo layout

terraform/           core infra (DynamoDB, RAG Lambda, IAM) + ECS hosting
lambda_rag/          RAG tool: token resolve -> de-identified evidence package
agent/               Strands agent for AgentCore Runtime + tool schema
presidio/            PII detector service (returns typed findings) + Dockerfile
seed/                fake customer (Wang Xiaoming) + seed script
ui/                  advisor UI with restored-vs-tokenized split view
scripts/             deploy.sh, agentcore_setup.sh, teardown.sh
fusion/              POLICY_SETUP.md  (the console/flow config — the manual part)

Prerequisites

aws-cli configured (creds + region), terraform >= 1.5, docker, python3, the AgentCore CLI (npm i -g @aws/agentcore), Bedrock model access enabled for bedrock_model_id, and an Axway Amplify AI Gateway (Fusion) container image you supply (fusion_image_uri).

Deploy

bash scripts/deploy.sh          # infra -> presidio image -> ECS -> seed -> AgentCore
# then: configure Fusion policy (fusion/POLICY_SETUP.md)
# then: point ui/index.html GATEWAY_URL at the Fusion host and open it

Demo script (maps to the 8 steps)

  1. Advisor UI: submit "請幫我整理王小明最近三個月的理財往來,並給我下次拜訪話術。"
  2. Fusion detects 王小明 + A123456789, tokenizes, logs tokens only.
  3. Show the Bedrock/AgentCore trace — the prompt the cloud saw contains CUST_000123. 4-6. Agent tool-calls back on-prem; RAG resolves the token, returns a summary.
  4. Agent writes talking points (no PII).
  5. Fusion restores 王小明; the UI shows the restored answer beside the tokenized view.

Teardown

bash scripts/teardown.sh        # stop paying for Fargate / AgentCore

Honest caveats

  • zh-TW detection is demo-narrow. Presidio here is tuned to the scripted entities; a smooth run is not evidence of production zh-TW recall — that remains the real-engagement risk.
  • Per-request randomization ("different each time") lives in the Fusion mint step (fusion/POLICY_SETUP.md); confirm it satisfies HNCB's requirement.
  • The agentic token-resolution loop (agent tool call → on-prem RAG resolves the token) is custom orchestration — it is not turnkey on any gateway, which is exactly where Fusion's orchestration depth is the argument.
Description
All-AWS demo: reversible PII de-identification round trip through Axway Amplify AI Gateway (Fusion) with an Amazon Bedrock AgentCore agent. HNCB use case.
Readme 182 KiB
Languages
HCL 40.5%
Python 35.5%
Shell 18.7%
HTML 4.8%
Dockerfile 0.5%