You can use Amazon's VPC to isolate your application in a virtual network that you define. By default, an application is available publicly at myapp.elasticbeakstalk.com. You can use security group rules to make it accessible based on your requirements. You can also easily control what other incoming traffic, such as SSH, is delivered or not to your application servers by changing the EC2 security group settings.