AWS Continuum Features
Features overview
AWS Continuum discovers, prioritizes, validates, and remediates security risks across the software lifecycle, at machine speed and within the guardrails you define. Before code ships, it finds risks in your designs and code. Once your systems are running, it decides which risks matter to your business, proves which are exploitable, and drives toward a fix.
Penetration testing
Open allAWS Continuum for penetration testing delivers on-demand testing by deploying specialized AI agents to discover and report validated security vulnerabilities, transforming periodic assessments to continuous validation. It identifies complex vulnerabilities through tailored multi-step attack scenarios by testing web applications and APIs against OWASP (Open Worldwide Application Security Project) Top 10 vulnerabilities as well as business logic flaws.
AWS Continuum for penetration testing validates security findings through exploitation, delivering reproducible exploit paths, comprehensive impact analysis, and ready-to-implement fixes in developer-friendly language. This helps teams prioritize legitimate high-impact security risks without wasting time on false positives.
AWS Continuum for penetration testing transforms slow and resource-intensive periodic penetration tests into ongoing testing that matches your development speed. With on-demand testing now available, organizations can expand penetration testing beyond just critical applications and secure their entire portfolio with the same resources.
AWS Continuum for code scanning understands your application's context by learning from your source code and documentation to identify and exploit vulnerabilities that automated security scanning tools can't find. By understanding your application context and data flows, it crafts targeted attack scenarios that validate real exploitable risks, not just surface-level findings. This context-aware testing uncovers the critical vulnerabilities that matter to your business.
Tested across hundreds of applications with customers including SmugMug, Wayspring, and HENNGE K.K., and internal AWS Pentest teams, the Continuum for penetrating testing consistently identifies legitimate critical vulnerabilities with high precision and recall matching human penetration testers. Continuum for penetration testing enables security teams to focus on complex attack vectors while maintaining comprehensive vulnerability coverage with minimal false positives.
Embed penetration testing directly into your development workflow through comprehensive API support. Trigger automated security tests from your CI/CD pipelines, integrate results into your existing tooling, and validate security at every deployment, enabling continuous security validation that matches your development velocity.
Secure complex, multi-account architecture without compromise. AWS Continuum for penetration testing supports cross-account VPC configurations, enabling penetration testing across your entire AWS infrastructure regardless of how you've organized accounts.
Generate comprehensive reports that include executive summaries, detailed findings with CVSS scores, remediation guidance, and compliance mappings. Export to PDF for distribution to security teams, compliance officers, or external auditors, providing documentation for reviews and regulatory assessments
Refine testing accuracy with every run. Provide direct feedback on findings — mark false positives, add context to vulnerabilities, or confirm exploits to deliver more relevant results in future tests, reducing noise and helping your team focus on issues that matter most to your applications.
Code vulnerabilities (Preview)
Open allAddresses the full lifecycle of a code vulnerability at machine speed: from discovery through actions. It reasons over your environment, confirms what is real, and drives toward resolution. It is model agnostic, using multiple frontier models where each performs best, and is built to incorporate the latest and most capable models as they emerge.
Proactive security
Open allAWS Continuum shifts security left by providing real-time security feedback on design documents and assessing compliance with organizational security requirements before any code is written. AppSec teams upload documents through a web application and receive remediation guidance and prioritize findings, accelerating review cycles. By proactively embedding your security standards into every design review, you reduce late-stage architectural rework and keep pace with multiple development teams.
AWS Continuum proactively secures applications by performing deep, reasoning-based analysis on every pull request and full repository to identify complex vulnerabilities that go beyond pattern-matching. It checks against your organizational security requirements and common security risks to catch what other tools can't. Developers receive fix commits and remediation guidance directly in their GitHub, GitLab, or Bitbucket workflow, while AppSec teams configure the repositories to be monitored and intervene on critical issues. Findings can be validated in simulated environments to show proof of exploitability. This embeds security expertise across repositories, reducing security-related delays in the development pipeline.
Continuum for code scanning deploys your application in a sandbox environment to dynamically confirm whether discovered vulnerabilities are exploitable. Available for full repo scans.
Catch risks at the design stage, before they become real vulnerabilities. Continuum for threat modeling generates STRIDE threat models from your design docs or code base, mapping your application's components, trust boundaries, and data flows to surface attack paths while they're still easy to address. It returns STRIDE-categorized threats, recommended mitigations, and open assumptions. By shifting security into the earliest design decisions, teams prevent vulnerabilities from entering the codebase, reducing costly late-stage redesigns.
AWS Continuum for penetrating testing executes on-demand tests to discover, and report validated security vulnerabilities through tailored multi-step attack scenarios. It documents these findings with impact analysis, reproducible attack paths and ready-to-implement code fixes, accelerating penetration testing from weeks to hours and scaling penetration testing across all applications, instead of just critical ones.
AWS Continuum for penetration testing operates across AWS, hybrid, and multicloud environments, providing consistent security guidance and testing, regardless of your infrastructure setup.
Conduct comprehensive security reviews with analysis of findings and manage penetration testing scopes across the entire organization through a web application.
Integrate Continuum capabilities directly into your workflows and toolchains with full-featured API and SDK support.
Continuum for code scanning connects to GitHub, GitLab, and Bitbucket — supporting both SaaS and self-hosted versions — so teams can trigger scans regardless of where code lives. With Kiro power for Continuum and the Claude Code plugin, run code reviews, generate threat models, and remediate findings directly from your IDE or CLI.
Scale testing operations with confidence. Service quotas define the maximum number of concurrent tests, applications under test, and API requests your account can execute. View current usage, monitor limits, and request increases directly through the console—ensuring your security testing scales alongside your development velocity without unexpected interruptions.
Maintain complete control over your encryption keys while leveraging Continuum capabilities. CMK support ensures your security data remains encrypted with keys you manage, meeting compliance requirements for regulated industries and enterprise security policies.
Organize and track security testing at scale. Apply custom tags to applications and agent spaces to align with your organizational structure — by team, environment, compliance framework, or business unit. Use tags to filter results, generate targeted reports, and allocate costs, making it easy to manage security testing across hundreds of applications and multiple teams.
Tailored guidance
Open allDefine your organization's security requirements once in the AWS console. AWS Continuum for penetration testing automatically validates using your specific policies across all applications during every security review, ensuring teams address the risks you care about, not generic security checklists.
Continuously validate your security requirements across every threat model, code review, and repo scan. Start with managed compliance packs for AWS WAF, NIST CSF and PCI DSS, or import your own organizational requirements directly from internal docs. Findings maps back to your compliance posture, so teams stay audit-ready as they build.
AWS Continuum for threat modeling analyzes your design documents, business requirements, and source code to understand each application before making security recommendations. By understanding your technology patterns, architecture decisions, and business context, the agent delivers guidance tailored to each application's unique risk profile across design reviews, code analysis, and penetration testing. You get security recommendations that fit your applications, not one-size-fits-all rules.
AWS Continuum leverages nearly two decades of AWS cloud and application security expertise along with AWS security best practices to provide comprehensive security guidance. AWS security infrastructure is trusted by some of the most security sensitive organizations such as the government, financial services, and healthcare.
Threat modeling (Preview)
Open allGenerate a context-aware STRIDE threat model based on your design docs or code base. Get prioritized, actionable mitigations across all six STRIDE categories through deep reasoning of your architecture, data flows, and trust boundaries.
Code scanning (Preview)
Open allPerform deep security analysis of your code against organizational compliance requirements, known exploit patterns, and emerging threat vectors — delivering actionable remediation guidance with validated fixes.