erm it's not coupled with Heroku at all? Where does it say that?
Your custom code is hosted on AWS in sandboxed environments that are only visible your team. But it has nothing to do with Heroku.
As an infrastructural developer who has an ear to the ground with regards to security concerns, I immediately don't trust unsubstantiated descriptions of "sandboxed environments", especially not ones with regard to tools that may become core to my business practices. Can you fully describe how you are isolating these systems?