That is the threat model, that is supposed to be safe isolated access in a vpc that isolated applications can access but it has external access.