Changes confirmed medium confidence

LangSmith BYOC Becomes Generally Available on AWS

LangChain says enterprise customers can keep sensitive agent data in their own AWS accounts while it manages the LangSmith platform lifecycle.

LangChain made LangSmith Bring Your Own Cloud generally available on Amazon Web Services on August 12. The release gives enterprise customers a managed LangSmith deployment whose data plane runs inside their own AWS account and virtual private cloud, while LangChain provisions and operates the platform, according to the official announcement.

The change is aimed at teams whose agent traces and runtime records can contain prompts, datasets, experiments, tool outputs and other sensitive context. LangChain says those application records stay in the customer's AWS environment. The company still manages monitoring, upgrades, scaling and the cluster lifecycle, creating a middle path between a conventional hosted service and infrastructure the customer operates alone.

How the control and data planes divide responsibility

The architecture separates LangSmith into two planes. LangChain runs the control plane in its own cloud and says that plane does not hold sensitive application data. The customer-account data plane contains the virtual private cloud, a private Amazon Elastic Kubernetes Service cluster, databases, object storage and the sensitive LangSmith records generated by agent work.

LangChain says communication between the two planes uses AWS PrivateLink and does not cross the public internet. It also describes the EKS cluster as private, with no public API-server endpoint and no public IP addresses on worker nodes. Those are concrete design boundaries, but they remain vendor-described architecture rather than independently tested security findings.

The split matters because it leaves important infrastructure and data assets under the customer's cloud ownership. LangChain says the customer owns the AWS account, VPC, databases, object storage and sensitive application data. The provider operates LangSmith on the customer's behalf rather than moving those records into LangChain's network.

What LangChain manages for customers

The managed portion covers infrastructure and LangSmith version upgrades, scaling, patching, backups and health monitoring. That could reduce the operational work required to maintain a private deployment, while preserving the customer's existing network boundary and cloud account controls. Whether the arrangement satisfies a particular security or compliance programme still depends on the buyer's own assessment; the announcement is not a certification or independent audit.

The documented audit paths also remain in the customer's environment. LangSmith audit logs live in the data plane, Amazon EKS audit logs go to Amazon CloudWatch in the customer account, and VPC flow logs are written to an Amazon S3 bucket the customer owns. These records give security and platform teams places to inspect access and network activity without changing the basic division of responsibilities.

Availability and current limits

LangSmith BYOC is available to Enterprise customers across 15 AWS regions in the United States, European Union and Asia-Pacific, according to LangChain. The announcement does not provide public pricing, migration-duration data, service-level results or region-by-region performance evidence. It also does not establish that the architecture will meet every customer's regulatory or internal-control requirements.

The feature boundary is still evolving. LangChain says Managed Deep Agents, its large-language-model authentication proxy and Engine are planned for BYOC support later, so buyers should verify that the LangSmith capabilities they need are available in the AWS deployment before treating it as a complete substitute for another hosting model.

What to verify next

The next useful checkpoints are operational rather than promotional: how long deployments and upgrades take, how failures are recovered, what support access looks like in practice, and whether customers can validate the stated network and data boundaries with their own logs and controls. Independent reliability, isolation, cost and migration evidence was not included in the fetched announcement.

Status

Confirmed product availability. Internal confidence is medium because the launch and architecture are documented by LangChain, but the fetched evidence contains no independent operational or security testing.

Sources

Update note: Last reviewed 2026-08-13. We will revise this post if LangChain changes regional access, the Enterprise-plan requirement, supported features or the documented operating model.

Sources

Drafted with AI assistance from source briefs; reviewed for citation completeness and label accuracy.

More Changes coverage