DealerIQ keeps authorization, data access and business controls in the application layer. Amazon Nova is used as a reasoning and generation component—not as a security boundary.
Application Architecture
Browser / DealerIQ UI
│ HTTPS
▼
Amazon API Gateway
│ throttling • CORS
▼
AWS Lambda
├────► DynamoDB • Customer Data (read)
├────► DynamoDB • Conversation Memory
└────► Amazon Bedrock
│ controlled context
▼
Amazon Nova 2 Lite
│
▼
Generated Response
Implemented Security & Governance
✓ Least-privilege application IAM
✓ No direct database access by the LLM
✓ Application-controlled model context
✓ API throttling: 5 req/s, burst 10
✓ Restricted browser CORS origin
✓ Request size, type & UUID validation
✓ Data-integrity / prompt-injection rules
✓ No autonomous business actions
✓ Human-review policy for communications
✓ Structured logging & request correlation
✓ Latency & token telemetry
✓ Synthetic demonstration customer data
Security boundary: The LLM is not trusted to authorize access or execute business operations. IAM, data retrieval, validation and policy enforcement remain in the application layer.
Production Enhancements
○ Cognito / enterprise SSO
○ Role-based authorization
○ Tenant-level data isolation
○ AWS WAF
○ Bedrock Guardrails
○ Centralized audit / SIEM integration
○ PII classification & redaction
○ Model evaluation / regression testing
○ Token / cost budgets and alarms
○ Scoped queries instead of demo table scans