Overview
Built on a standardized AWS architecture
Every BYOC data plane is provisioned from a standardized architecture similar to the one LangChain uses to run LangSmith Cloud.
Built on a standardized AWS architecture
Communication stays private.

Product video
LangSmith BYOC on AWS - A Managed Agent Engineering Platform in Your Own Cloud
LangSmith Bring Your Own Cloud (BYOC) gives enterprises a fully managed LangSmith deployment that runs inside their own AWS account and VPC. Sensitive application data - including traces, datasets, experiments, prompts, agent deployments, and sandbox data - stays in your AWS environment. LangChain provisions and operates the deployment, handling monitoring, upgrades, scaling, and cluster lifecycle management.
Why BYOC?
Teams taking AI agents from pilot to production often hit a common blocker: agent traces and runtime data include PII, PHI, customer records, internal API responses, tool outputs, and other sensitive context. These teams need LangSmith's observability, evaluation, deployment, and management capabilities, but they also need data to remain inside the cloud boundary they already govern.
With LangSmith BYOC on AWS, you can:
- Keep sensitive data in your own AWS account and VPC - no traces, datasets, or prompts leave your environment
- Spend less time on infrastructure and more time building, evaluating, and improving agents
- Scale agent development across teams and regions while keeping agents close to private systems
- Connect agents to internal systems - databases, private APIs, and on-premises resources over existing network paths
BYOC is available across 15 AWS regions in the US, EU, and APAC.
How It Works
A BYOC deployment runs across two planes:
Control Plane (LangChain's cloud): Handles authentication, user management, workspace configuration, billing metadata, and the LangSmith frontend. It provisions, monitors, and orchestrates customer data planes. The control plane does not hold sensitive application data.
Data Plane (your AWS account): Contains the VPC, private Amazon EKS cluster, databases, object storage, and all sensitive LangSmith data. Communication between planes uses AWS PrivateLink and does not cross the public internet. The EKS cluster is private with no public API server endpoint and no public IPs on worker nodes.
Standardized AWS Architecture
Every BYOC data plane includes:
- A dedicated VPC in your AWS account
- A private Amazon EKS cluster with no public endpoints
- Daily backups for Amazon RDS and the trace store, written to Amazon S3 in your account
- Autoscaling for LangSmith services and node capacity
- Multi-AZ Amazon RDS and Amazon ElastiCache with automatic failover
- Auditable operational access with logs in your account via Amazon CloudWatch and Amazon S3
LangChain provisions infrastructure using Crossplane. You create an IAM role with a provided Terraform module, scoped to infrastructure management with permissions limited to resources tagged managed_by=langsmith.
LangSmith Features Available on BYOC
- Observability: Tracing, projects, dashboards, and alerts
- Evaluation: Datasets, experiments, evaluators, and annotation queues
- Insights: Automatic analysis of traces to surface usage patterns and failure modes
- Context Hub: Prompts, memory, and other context files
- Agent Deployment: Deploy and manage agents inside your data plane
- Sandboxes: Code execution on a dedicated node group in your account
- LLM Gateway: Centralized model access with spend, rate limit, and data protection policies
- Fleet: Build and run no-code agents
- SmithDB: Observability backend for trace data, persisting to Amazon S3 in your account
Operational Simplicity
LangChain handles infrastructure upgrades, LangSmith version upgrades, scaling, patching, backups, and health monitoring. Setup requires applying a Terraform module and creating a data plane in LangSmith. Additional data planes can be created across environments, AWS accounts, and regions with organization-level configuration carried across deployments.
Built for Regulated Environments
LangSmith BYOC is designed for teams in financial services, healthcare, cybersecurity, and large enterprises with strict data governance requirements. LangSmith BYOC is available on AWS for customers on the LangSmith Enterprise plan.
Highlights
- Data Residency in Your AWS Account: Sensitive application data - including traces, datasets, experiments, prompts, agent deployments, and sandbox data - stays in your own AWS account and VPC, in the region you choose. Communication between the control plane and data plane uses AWS PrivateLink and never crosses the public internet. Audit logs, EKS audit logs, and VPC flow logs all remain in your account.
- Fully Managed Operational Lifecycle by LangChain: LangChain handles infrastructure upgrades, LangSmith version upgrades, scaling, patching, backups, and health monitoring so your engineering teams can focus on building and improving agents. Setup uses a Terraform module to create an IAM role, and LangChain provisions the VPC, EKS cluster, databases, storage, and services. Additional data planes can scale across environments, AWS accounts, and 15 regions in the US, EU, and APAC.
- Complete Agent Engineering Capabilities: BYOC includes observability with tracing, dashboards, and alerts; evaluation with datasets, experiments, and annotation queues; Insights for automatic trace analysis; Context Hub for prompts and memory; agent deployment and sandboxes running in your data plane; LLM Gateway for centralized model access with spend and rate limit policies; Fleet for no-code agents; and SmithDB persisting trace data to Amazon S3 in your account.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Trust Center
Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
LangSmith BYOC on Amazon EKS
- Amazon EKS
- Amazon EKS Anywhere
Helm chart
Helm charts are Kubernetes YAML manifests combined into a single package that can be installed on Kubernetes clusters. The containerized application is deployed on a cluster by running a single Helm install command to install the seller-provided Helm chart.
Version release notes
Initial AWS Marketplace BYOC release, including Helm chart 0.16.31 and LangSmith 0.16.66. Includes runtime components and supporting dependencies for Linux AMD64, with image references configured to use this product's AWS Marketplace repository.
Additional details
Usage instructions
This delivery option provides runtime artifacts for LangSmith BYOC on Amazon EKS. LangChain coordinates deployment and operates the BYOC infrastructure in your AWS account.
-
Coordinate BYOC enablement with your LangChain representative.
-
Follow the AWS BYOC setup guide to configure the required IAM role and onboard your AWS account: https://docs.langchain.com/langsmith/byoc
-
Create your AWS data plane through LangSmith using the IAM role and region configured during onboarding.
For deployment assistance or troubleshooting, contact your LangChain representative or visit: https://support.langchain.com/
Resources
Vendor resources
Support
Vendor support
LangSmith BYOC is available for customers on the LangSmith Enterprise plan. For support inquiries, deployment questions, or to enable BYOC for your organization, contact the LangChain team directly.
LangSmith customers can also access LangChain's support portal at https://support.langchain.com/ . Visit the portal to submit requests, report issues, or get help with platform functionality including tracing, evaluation, and deployment.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.