Skip to main content

AWS Continuum FAQs

General

Open all

    AWS Continuum discovers, prioritizes, validates, and remediates security risks across the software lifecycle, at machine speed and within the guardrails you define. Before code ships, it finds risks in your designs and code. Once your systems are running, it decides which risks matter to your business, proves which are exploitable, and drives toward a fix.

    AWS Continuum offers a frontier agent that proactively secures your applications throughout the software development lifecycle. It conducts automated security reviews tailored to your organizational requirements and delivers context-aware penetration testing on demand. By continuously validating security from design to deployment, it helps prevent vulnerabilities early in development.

    With the pace of development accelerating through the integration of coding tools, customers need to prioritize proactive security. AWS Continuum makes it possible for security teams to shift from reactive incident response to proactive risk prevention by providing always-available security guidance to every developer during development. While traditional "shift-left" approaches often burden developers with more security tasks, AWS Continuum acts as an always-present AI-powered agent that proactively identifies risks, suggests secure patterns, and validates implementations. Continuum conducts automated security reviews during design and coding phases that are tailored to your organization’s security requirements. When applications are ready for deployment, on-demand penetration testing helps prevent costly security issues before they reach production. Traditional penetration testing is time-consuming and expensive, limiting customers to test only their most critical applications periodically (annually or quarterly). AWS Continuum provides on-demand testing that identifies legitimate vulnerabilities in the customer’s application by discovering and then verifying risks through exploits using the application context. This helps your team scale penetration testing across their application portfolio. It also suggests code fix to address findings and provides automated remediation, helping close the loop between identification and remediation of security risks faster. 

    AWS Continuum for penetration testing delivers on-demand testing by deploying specialized AI agents to discover and report validated security vulnerabilities, transforming periodic assessments to continuous validation. When you open the Continuum console for the first time, simply click the Set up button and create your first agent space to perform security reviews on your applications. We recommend creating an agent space unique to an application you want to test. Administrators can configure security requirements, setup penetration testing, create agent spaces, and manage user access in the console. Then, users can log in to the web application to perform a design review and to run a penetration test. For more details, visit the user guide and the pricing page.

    AWS Continuum for code vulnerabilities (Preview) addresses the full lifecycle of a code vulnerability at machine speed: from discovery through actions. It reasons over your environment, confirms what is real, and drives toward resolution. It is model agnostic, using multiple frontier models where each performs best, and is built to incorporate the latest and most capable models as they emerge. Sign up for the gated preview

    No. AWS Continuum for penetration testing starts with the OWASP Top 10 but is customized by the context it learns about the customer’s application from their documents and code. AWS Continuum for penetration testing adapts itself to the responses it gets back from building a custom attack plan for the customer’s application.

    AWS DevOps Agent and AWS Continuum are different but complementary. Use AWS DevOps Agent release management to check for dependencies, configuration issues, and deployment hygiene to verify your deployment does not break production. Use AWS Continuum to discovers, prioritizes, validates, and remediates security risks across the software lifecycle, at machine speed and within the guardrails you define. It also performs threat modeling, conduct on-demand penetration testing, and automated security reviews to surface vulnerabilities across the SDLC so developers can build secure applications from the start.

Getting started

Open all

    Yes. Customers do need an AWS account to use AWS Continuum for penetration testing.

    Once Continuum for penetration testing is enabled, it can point to any application that is in AWS (private and public endpoints), on premises, hybrid, or in other cloud environments.

Security

Open all

    No. AWS Continuum doesn’t use customer data for model training, and it doesn’t share customer data with third parties. 

    All customer data is encrypted at rest using AWS KMS. 

    Test logs are stored in CloudWatch in the customer’s account.

    AWS Continuum has built-in, flexible authentication through static credentials, IAM roles, API keys, and dynamic via services like AWS Secrets Manager or dynamically accessed credentials (through Lambdas), giving customers fine-grained access control through granular access management with strict permissions.

Pricing

Open all

    AWS Continuum for penetration testing uses pay-as-you-go pricing billed at $50/task-hour. The service also offers a 2-month free trial. For more details, please refer to the pricing page

    Yes. Customers who participated in the Public Preview are eligible for the 2-month free trial. The trial begins when you create your first penetration test run after general availability. Pricing details are available on the AWS Continuum pricing page.

    Yes, design review, code review, and threat modeling features are in preview and not billed. You continue to get up to 200 design reviews per account per month and 1,000 code reviews per account per month.

Did you find what you were looking for today?

Let us know so we can improve the quality of the content on our pages