Free trial Agent Fleet Manager · trial builds work until 1 January 2027 Questions? Contact us →
EntPEP Free trial
Start the install
Free trial · your AWS account

Run your own EntPEP appliance.

Two servers, two installers. Let Claude Code run the install for you in about 15 minutes, or follow the guide by hand. Your agents run in sealed VMs on your agent host; your data lake and an optional private model run on the second server. Nothing goes through us.

Use Claude through your Anthropic API key, Claude on Amazon Bedrock in your own AWS account, or the private model on your data server. Trial builds stop working on 1 January 2027.

The quick path

Let Claude install it.

One instructions file turns Claude Code into your installer. It asks a few questions, then runs every command on your computer and on both servers, checks each result, and stops to ask before it creates anything that costs money.

  1. Have ready: Claude Code, the AWS CLI signed in to your account (aws login), two DNS names you can point (host. and data.yourdomain.com), and a model: an Anthropic API key, Claude on Amazon Bedrock, or none (the private model).
  2. In an empty folder, start claude and paste:
    Download https://entpep.com/dl/entpep-trial-install.md with curl, read it, and step me through the EntPEP trial install.
  3. Choose how the AWS pieces get made. Claude can create the key pair, security groups, fixed addresses and both servers itself, or you click them together in the AWS console from its list and it takes over from there (including turning on nested virtualization, which the console can't).
  4. Add your DNS records when it shows you the two addresses. It installs the data server, copies the data lake logins across, installs the agent host, and hands you the Fleet Manager URL with the password on your clipboard.
  5. SharePoint and the demo. It walks your Microsoft 365 admin through the one-site Entra app, then sets up the demo.

Passwords and keys move between the servers by pipe or go to your clipboard; Claude never asks you to paste a secret into the chat. If Claude Code's safety check holds back a command, Claude asks you to run it yourself with !. Read the instructions file.

our test run · 4 October 2026

About 15 minutes to a working install

0:00Questions and account checks
~0:04Key pair and addresses created; both servers launched
~0:05Both servers up
~0:06Data server: NVIDIA driver, reboot, the 9 GB model, ClickHouse and demo data
~0:12Agent host install
~0:15SharePoint connected: working install

That run had DNS ready, the GPU quota already approved and a SharePoint app that already existed. A first install usually takes 30-60 minutes; new AWS accounts may need a day for the GPU quota, and the Microsoft 365 steps take your admin about 20 minutes.

What you'll build

An agent host, a private server, and the model of your choice.

Everything runs in your AWS account, under your names. The only things you download from us are two installers and the demo files.

host.yourdomain.com

Agent host

The Agent Fleet Manager on port 443. Each agent is a sealed unikernel VM with its own browser tab on ports 8001-8008, launched with only the sources you approve. Audit, grants, sub-agents and the SharePoint connection live here.

m8i.2xlarge · nested virtualization · Ubuntu 26.04 · about $0.42/hour
data.yourdomain.com

Private server

A ClickHouse data lake with the demo trade blotter, behind nginx on 8443 with an IP allowlist and passworded desk logins. Plus a private model (qwen3:14b on an NVIDIA L4) on 443 if you want nothing to leave your servers.

g6.xlarge · NVIDIA L4 24 GB · Ubuntu 26.04 · about $0.80/hour
model option

Anthropic API

Paste your Anthropic API key during the install. The quickest start.

model option

Claude on Amazon Bedrock

Claude in your own AWS account, with an IAM user that may only call Claude and a Bedrock API key. Counts as an internal model.

model option

Private model

qwen3:14b on your data server. No outside model at all. Slower and simpler answers than Claude, and the demo still works.

Every model gets the same hooks, grants and audit trail. You also need a Microsoft 365 admin for about 20 minutes: the demo's files live in one SharePoint site that the host can reach and nothing else.

Videos

See the install, then the demo you'll run.

Install walkthrough (1:44): AWS setup, the private server's two passes, the agent host, SharePoint and the model choice. MP4
The demo: a counterparty credit review. A credit risk VP's agent reads her files, pulls exposure from the data lake, is blocked from data she wasn't granted, and saves a memo. Simulated data. MP4 · PDF
Agent Fleet Manager tour: launching sealed agents, model servers, labels and the blocked launch, sub-agents, row-level data and the audit trail. MP4 · PDF
Downloads

Everything for the trial.

The installers are fetched on the servers themselves with curl (step 6 and 8 of the guide). The rest is for you and your Microsoft admin.

Markdown

Claude install instructions

Give this file to Claude Code and it runs the whole install with you: AWS, both servers, the model, SharePoint and the demo.

PDF

Install guide

Both servers from nothing: AWS, DNS, the two installs, SharePoint, the model, the demo, teardown and troubleshooting. Also below on this page.

PDF

Microsoft setup

For your Microsoft 365 admin: the SharePoint site, the Entra app with Sites.Selected, the certificate and the one-site grant.

PDF

Demo script

The nine-step credit review demo, about 10 minutes, with every prompt to paste and what you should see.

ZIP

Demo files

The six simulated files for the SharePoint source folder: limits workbook, last year's review, policy excerpt, memo template, analyst notes, the desk's request.

tgz · 7 MB

Agent host installer

The Fleet Manager, the sealed agent and its hypervisor, with install.sh. Trial build, works until 2027-01-01.

sha256 45e141fdf474ecfb2e7125b66db9b8bdf00c971bb5d3554a1a115864bdc1ac54
tgz · 13 KB

Private server installer

ClickHouse with the demo data and its nginx bridge, the NVIDIA driver, Ollama and the private model, with install.sh.

sha256 4f24184fdac22331fe9bcb4c8fdef82883cfc8fc43cf0a9db4163ba558f37f78
Install guide

Or do it by hand.

The same install, step by step. Every command is one line: use the Copy buttons. Commands in steps 1-5 and 7 run on your computer with the AWS CLI; step 6 on the data server; steps 8-9 on the agent host.

your browser ──443──▶ host  (Agent Fleet Manager; each agent on its own port 8001-8008)
                       │  model calls ──▶ Anthropic API, or Claude on Amazon Bedrock,
                       │                  or ──443──▶ data (private model, qwen3:14b)
                       └─ data lake   ──8443──▶ data (ClickHouse, demo trade blotter)

What you need

ItemRequirement
AWS accountRights to create instances, Elastic IPs and security groups. The AWS CLI v2, signed in (aws login or aws configure)
GPU quotaRunning On-Demand G and VT instances at least 4 vCPUs (quota code L-DB2E81BA). New accounts often have 0; request it first, it can take a day
Two DNS nameshost.yourdomain.com and data.yourdomain.com, A records you can edit
Microsoft 365A tenant admin for about 20 minutes: a SharePoint site holds the demo files, and an Entra app gives the host access to that one site only
A modelAny of three: an Anthropic API key; a Bedrock API key (Claude in your own AWS account); or the private model on the data server (no outside model at all)

Cost: about $1.25/hour with both running (m8i.2xlarge about $0.42, g6.xlarge about $0.80), plus about $15/month for disks and the two addresses. Stop both when you're not using them.

Ports

ServerInbound portFromWhy
hostTCP 443your users' addressesthe Agent Fleet Manager
hostTCP 8000-8999your users' addresseseach agent opens in its own browser tab on its own port (8001-8008 today)
hostTCP 22your addressSSH
hostTCP 80anywhereLet's Encrypt certificate
dataTCP 443the host's addressthe private model's API
dataTCP 8443the host's addressthe data lake (ClickHouse behind nginx, IP allowlist)
dataTCP 22your addressSSH
dataTCP 80anywhereLet's Encrypt certificate

The host needs outbound HTTPS to the model (api.anthropic.com or Bedrock), to login.microsoftonline.com, graph.microsoft.com and your SharePoint host, and to the data server.

1. On your computer: names and settings

Paste these one at a time (macOS or Linux shell; change the first three):

H=host.yourdomain.com
D=data.yourdomain.com
REGION=us-east-2
MYIP=$(curl -s https://checkip.amazonaws.com)/32
VPC=$(aws ec2 describe-vpcs --region $REGION --filters Name=is-default,Values=true --query 'Vpcs[0].VpcId' --output text)
AZ=$(aws ec2 describe-instance-type-offerings --region $REGION --location-type availability-zone --filters Name=instance-type,Values=g6.xlarge --query 'InstanceTypeOfferings[0].Location' --output text)
SUBNET=$(aws ec2 describe-subnets --region $REGION --filters Name=vpc-id,Values=$VPC Name=availability-zone,Values=$AZ --query 'Subnets[0].SubnetId' --output text)
AMI=resolve:ssm:/aws/service/canonical/ubuntu/server/26.04/stable/current/amd64/hvm/ebs-gp3/ami-id
echo "vpc $VPC  zone $AZ  subnet $SUBNET"

An SSH key pair (skip if you have one; then set KEY to its name):

KEY=entpep-trial; aws ec2 create-key-pair --region $REGION --key-name $KEY --query KeyMaterial --output text > ~/.ssh/$KEY.pem && chmod 600 ~/.ssh/$KEY.pem
SSHK="-i $HOME/.ssh/$KEY.pem"

Check the GPU quota is at least 4: aws service-quotas get-service-quota --region $REGION --service-code ec2 --quota-code L-DB2E81BA --query Quota.Value

2. Two fixed addresses (Elastic IPs)

Fixed addresses keep the DNS records and the data server's allowlist right after a stop and start.

HALLOC=$(aws ec2 allocate-address --region $REGION --domain vpc --query AllocationId --output text)
DALLOC=$(aws ec2 allocate-address --region $REGION --domain vpc --query AllocationId --output text)
HIP=$(aws ec2 describe-addresses --region $REGION --allocation-ids $HALLOC --query 'Addresses[0].PublicIp' --output text)
DIP=$(aws ec2 describe-addresses --region $REGION --allocation-ids $DALLOC --query 'Addresses[0].PublicIp' --output text)
echo "host $H = $HIP   data $D = $DIP"

3. DNS

Two A records at your DNS provider: $H → $HIP and $D → $DIP. On Cloudflare, set them to DNS only (grey cloud), not proxied. Check: dig +short $H; dig +short $D

4. Security groups

HSG=$(aws ec2 create-security-group --region $REGION --vpc-id $VPC --group-name entpep-host --description "EntPEP agent host" --query GroupId --output text)
aws ec2 authorize-security-group-ingress --region $REGION --group-id $HSG --protocol tcp --port 22 --cidr $MYIP
aws ec2 authorize-security-group-ingress --region $REGION --group-id $HSG --protocol tcp --port 443 --cidr $MYIP
aws ec2 authorize-security-group-ingress --region $REGION --group-id $HSG --protocol tcp --port 8000-8999 --cidr $MYIP
aws ec2 authorize-security-group-ingress --region $REGION --group-id $HSG --protocol tcp --port 80 --cidr 0.0.0.0/0
DSG=$(aws ec2 create-security-group --region $REGION --vpc-id $VPC --group-name entpep-data --description "EntPEP private server" --query GroupId --output text)
aws ec2 authorize-security-group-ingress --region $REGION --group-id $DSG --protocol tcp --port 22 --cidr $MYIP
aws ec2 authorize-security-group-ingress --region $REGION --group-id $DSG --protocol tcp --port 443 --cidr $HIP/32
aws ec2 authorize-security-group-ingress --region $REGION --group-id $DSG --protocol tcp --port 8443 --cidr $HIP/32
aws ec2 authorize-security-group-ingress --region $REGION --group-id $DSG --protocol tcp --port 80 --cidr 0.0.0.0/0

To let colleagues use the Fleet Manager, add their addresses to the host's 443 and 8000-8999.

5. Launch both servers

The agent host must have nested virtualization on: each agent runs in its own small VM. The AWS web console has no setting for it, so launch from the CLI.

HID=$(aws ec2 run-instances --region $REGION --instance-type m8i.2xlarge --image-id $AMI --cpu-options NestedVirtualization=enabled --key-name $KEY --subnet-id $SUBNET --security-group-ids $HSG --metadata-options HttpTokens=required,HttpEndpoint=enabled --block-device-mappings 'DeviceName=/dev/sda1,Ebs={VolumeSize=30,VolumeType=gp3,Encrypted=true}' --tag-specifications 'ResourceType=instance,Tags=[{Key=Name,Value=EntPEP-Host}]' --query 'Instances[0].InstanceId' --output text)
DID=$(aws ec2 run-instances --region $REGION --instance-type g6.xlarge --image-id $AMI --key-name $KEY --subnet-id $SUBNET --security-group-ids $DSG --metadata-options HttpTokens=required,HttpEndpoint=enabled --block-device-mappings 'DeviceName=/dev/sda1,Ebs={VolumeSize=80,VolumeType=gp3,Encrypted=true}' --tag-specifications 'ResourceType=instance,Tags=[{Key=Name,Value=EntPEP-Data}]' --query 'Instances[0].InstanceId' --output text)
aws ec2 wait instance-running --region $REGION --instance-ids $HID $DID
aws ec2 associate-address --region $REGION --instance-id $HID --allocation-id $HALLOC
aws ec2 associate-address --region $REGION --instance-id $DID --allocation-id $DALLOC
aws ec2 describe-instances --region $REGION --instance-ids $HID --query 'Reservations[0].Instances[0].CpuOptions.NestedVirtualization'

The last line must print "enabled". Write down HID and DID (echo $HID $DID) for later.

Launched the host from the web console? Stop it, turn nested virtualization on, start it: aws ec2 stop-instances --region $REGION --instance-ids $HID && aws ec2 wait instance-stopped --region $REGION --instance-ids $HID && aws ec2 modify-instance-cpu-options --region $REGION --instance-id $HID --nested-virtualization enabled && aws ec2 start-instances --region $REGION --instance-ids $HID

6. Install the private server (data)

ssh $SSHK ubuntu@$D, then on data. In the commands below, replace data.yourdomain.com, you@yourdomain.com (for Let's Encrypt) and HOST_IP (the host's Elastic IP, $HIP).

Pass 1 installs the NVIDIA driver and stops:

curl -sSfO https://entpep.com/dl/combined-private-install-v1.tgz && tar xzf combined-private-install-v1.tgz && cd combined-private-install-v1
sudo ./install.sh --hostname data.yourdomain.com --certbot you@yourdomain.com --allow HOST_IP
sudo reboot

Log in again. Pass 2 (about 5 minutes) installs the model, ClickHouse with the demo data, and the two nginx front doors, then checks them:

cd combined-private-install-v1 && sudo ./install.sh --hostname data.yourdomain.com --certbot you@yourdomain.com --allow HOST_IP

It must end with == Done (not WITH ERRORS) after four checks: the model answers, the model is on the GPU, entpep_host reads trade_blotter (37 rows), and the admin login is refused (403).

7. Copy the data lake logins to the host (on your computer)

Two passwords move from data to host without being printed:

for n in host desk; do ssh $SSHK ubuntu@$D "sudo cat /etc/entpep-datalake/$n.pass" | ssh $SSHK ubuntu@$H "umask 077; cat > ch-$n.pass"; done

8. Install the agent host

ssh $SSHK ubuntu@$H, then on the host (replace the two names and the email):

curl -sSfO https://entpep.com/dl/entpep-install-v1.tgz && tar xzf entpep-install-v1.tgz && cd entpep-install-v1
sudo ./install.sh --hostname host.yourdomain.com --certbot you@yourdomain.com --clickhouse-url https://data.yourdomain.com:8443/ --clickhouse-user entpep_host --clickhouse-password-file ~/ch-host.pass --clickhouse-desk-password-file ~/ch-desk.pass
shred -u ~/ch-host.pass ~/ch-desk.pass

It asks for an Anthropic API key: paste it, or press Enter if you'll use Bedrock or the private model (step 10). The summary should show:

  • data lake: https://data.yourdomain.com:8443/ answers as entpep_host

  • Trial build: works until 2027-01-01

  • Fleet Manager: https://host.yourdomain.com/

Sign in at https://host.yourdomain.com/ with any name and the password from sudo cat /opt/entpep/fleetcerts/fleet.pass.

9. SharePoint (your Microsoft 365 admin, about 20 minutes)

The host signs in to Microsoft as its own Entra app with a certificate it made during the install. The app can reach one SharePoint site and nothing else (Sites.Selected). The full walkthrough is the Microsoft setup PDF; in short:

  1. Get the host's certificate (public half only; the private key stays on the host). On your computer: ssh $SSHK ubuntu@$H "cat /opt/entpep/sharepoint-app.cer" > sharepoint-app.cer

  2. Create a SharePoint team site, e.g. EntPEP Trial, private. In its Documents library create a folder Barclays with two folders inside it, source and reports, and upload the six demo files (EntPEP-Trial-Demo-Files.zip from entpep.com/trial, unzipped) into Barclays/source. Optional, for the demo's "check every file" step: also upload the zip's Legal Agreements folder (28 files, with Legal's clause library in standards/) as a top-level folder, with an empty reports folder inside it.

  3. Register an Entra app (Entra → App registrations → New registration, single tenant, no redirect URI). Copy the Application (client) ID and Directory (tenant) ID. API permissions: remove User.Read, add Microsoft Graph → Application → Sites.Selected, Grant admin consent.

  4. Upload the certificate (sharepoint-app.cer) under the app's Certificates & secrets → Certificates. (Not under "Certificate authorities": that's tenant-wide trust for user sign-in.)

  5. Grant the app the one site in Graph Explorer (https://developer.microsoft.com/graph/graph-explorer, signed in as the admin): GET https://graph.microsoft.com/v1.0/sites/<tenant>.sharepoint.com:/sites/<SiteAddress> and copy the top-level id; then POST https://graph.microsoft.com/v1.0/sites/<site id>/permissions with {"roles":["write"],"grantedToIdentities":[{"application":{"id":"<client id>","displayName":"EntPEP Trial"}}]}. Expect 201 Created.

  6. On the host, in entpep-install-v1: sudo ./install.sh --entra-tenant TENANT_ID --entra-client CLIENT_ID --sharepoint-site "SITE_ID" (the site ID has commas: keep the quotes). It should end with SharePoint library: EntPEP Trial / Documents.

10. Choose the model

In the Fleet Manager: Admin → Model. You can enable more than one and pick per agent at launch.

Anthropic API. The key you pasted during the install. To add or change it later, on the host: umask 077; cat > ~/a.key (paste, Enter, Ctrl-D), then sudo ./install.sh --anthropic-key-file ~/a.key && shred -u ~/a.key.

Claude on Amazon Bedrock (your AWS account; counts as an internal model). Once per account, open the Bedrock console's Model access page and complete Anthropic's use-case form. Then, on your computer, a user that may only call Claude, and an API key for it:

ACCT=$(aws sts get-caller-identity --query Account --output text); aws iam create-user --user-name entpep-bedrock
aws iam put-user-policy --user-name entpep-bedrock --policy-name invoke-claude-only --policy-document "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Action\":[\"bedrock:InvokeModel\",\"bedrock:InvokeModelWithResponseStream\"],\"Resource\":[\"arn:aws:bedrock:*::foundation-model/anthropic.*\",\"arn:aws:bedrock:*:$ACCT:inference-profile/*anthropic.*\"]},{\"Effect\":\"Allow\",\"Action\":\"bedrock:CallWithBearerToken\",\"Resource\":\"*\"}]}"
aws iam create-service-specific-credential --user-name entpep-bedrock --service-name bedrock.amazonaws.com --credential-age-days 90 --query ServiceSpecificCredential.ServiceCredentialSecret --output text

The last line prints the key. In Admin → Model → Amazon Bedrock: region (e.g. us-east-2), model ID us.anthropic.claude-sonnet-5, the key, Test & enable.

Private model on data (nothing leaves your servers). On data: sudo head -1 /etc/entpep-llm/keys. In Admin → Model → Private server: host data.yourdomain.com, model qwen3:14b, the key, Test & enable. A 14B model is slower and less precise than Claude: the demo works, with simpler answers.

Keep confidential data internal (Admin, off by default): turn it on to show the policy. Agents that can reach the data lake are then labelled confidential and may use only Bedrock or the private model; an Anthropic-API agent with the data lake is refused at launch.

11. Run the demo

The Demo script PDF has the full script (about 10 minutes, nine steps, prompts to paste). Setup:

  1. Data Lake card: hover Connected, click manage, Grant 1h on trade_blotter only.

  2. SharePoint card: on, folder Barclays, Read-write, RAM workspace 512 MB.

  3. Data Lake card: dropdown All desks. Advanced: Sub-agents 1, Archive New.

  4. Launch Agent. The agent opens in a new tab on port 8001 and lists the 6 files.

Then ask it what decision is waiting, pull the exposure by desk from the data lake (Rates is at 88.7% of its limit), show the Credit desk seeing only its own rows, show the blocked comms_surveillance query, start a sub-agent, write the memo to SharePoint, and open the Data Lake tab for the audit trail.

12. The trial

Trial builds of both binaries stop working on 1 January 2027 (UTC). In the last 30 days the Fleet Manager shows the days left; after the date it shows a notice, running agents stop and new ones can't start. A licensed build installs over the trial as a normal upgrade and keeps your settings and archives. To continue, use the form at https://entpep.com/trial.

13. Stop or remove

Stop both (compute billing stops; disks and addresses still cost a little): aws ec2 stop-instances --region $REGION --instance-ids $HID $DID. Start them again with start-instances; the Elastic IPs keep the names working.

Remove everything: aws ec2 terminate-instances --region $REGION --instance-ids $HID $DID, then once they're gone, aws ec2 release-address --region $REGION --allocation-id $HALLOC, aws ec2 release-address --region $REGION --allocation-id $DALLOC, aws ec2 delete-security-group --region $REGION --group-id $HSG and the same for $DSG. In Entra, delete the app registration; in SharePoint, delete the site.

Troubleshooting

SymptomFix
run-instances: InsufficientInstanceCapacity or UnsupportedThat zone has no g6 or m8i right now: pick another AZ and SUBNET in step 1
run-instances: VcpuLimitExceeded for g6GPU quota (step 1): request 4 or more vCPUs in Service Quotas
data: nothing installed after the first runThat was pass 1 (driver): sudo reboot, then run it again
certbot failsThe DNS record isn't there yet, is proxied, or port 80 is closed
host: install: no /dev/kvmNested virtualization is off: the fix under step 5
host: port 443 is in useAnother web server is on the host: remove it
Data Lake card: grant failed: HTTP Error 403 … nginxdata doesn't allow the host's address: on data, sudo entpep-datalake allow HOST_IP
SharePoint: AADSTS700027The certificate isn't on the app registration (step 9.4)
SharePoint: HTTP Error 403The site grant (step 9.5) is missing or names another app or site
Agent stuck on "Starting your sealed agent…"Open 8000-8999 on the host's security group from your address
Private model: Test failsdata's security group must allow 443 from the host's address

Questions, or a licensed build: https://entpep.com/trial (the form at the bottom).

Questions, or ready to continue?

Talk to us.

Stuck on a step, want a hand with the install, or want a licensed build before the trial ends on 1 January 2027? Send us a note.

Back to the guide