The Composable Agentic Platform (CAP) is the TomorrowX Data Mediation™ platform: Programmable Data Agents observe, govern and transform live traffic without changing your systems. Agents operate in the data path between systems, terminating connections at the protocol level and processing requests and responses in flight, so capability is added between systems, not inside them. CAP Console composes solutions from pre engineered, security and performance tested components and deploys them across the agent fleet. Built for enterprise and public sector organisations, CAP enables governed AI adoption, cyber uplift, legacy system extension and interoperability without invasive change, rewrites, centralising data or forced migration, including in highly regulated, secure and air gapped environments.
The Composable Agentic Platform (CAP) is the TomorrowX Data Mediation™ platform, a control architecture that ensures the right data, context and controls participate in every AI, cyber and interoperability workflow. CAP is not an application platform or an embedded rules engine. Programmable Data Agents operate in the data path itself, terminating connections at the protocol level, processing live requests and responses in flight and passing traffic on, all without changes to the systems on either side. Capability is added between systems, not inside them, so organisations can observe, govern, transform, simulate and augment interactions without rewriting, migrating or directly integrating the applications involved.
CAP Console is the composition and operations environment. Teams assemble solution logic, user experiences and operational workflows from pre engineered, security and performance tested components, reuse proven building blocks, prototype with agility and move proven designs into production across web and multi protocol environments. This reduces delivery effort, shortens development cycles and accelerates deployment.
Built for enterprise and public sector organisations operating in highly regulated, secure and air gapped environments, CAP enables governed AI adoption, cyber uplift, legacy system extension and interoperability without invasive change, major redevelopment, centralising data or forced migration. Interventions can be proven, changed or removed without making the surrounding estate dependent on an irreversible transformation.
The Enterprise Edition includes the full TomorrowX library of plug and play functional and programming components, giving teams a repeatable foundation for composing production ready solutions at speed, closer to where systems, controls and operational requirements already exist.
Highlights
Data Mediation™ in the data path: Programmable Data Agents observe, govern and transform live traffic at the protocol level, without changing the systems on either side.
Connect AI and cyber capabilities to existing systems without invasive change, application rewrites, centralising data or forced migration, including in regulated, secure and air-gapped environments.
Compose web and multi-protocol solutions from pre-engineered, security and performance tested components, and move proven designs into production at speed.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay by the hour based on the AWS EC2 instance type you run. All ten dimensions bill on the same usage model, so cost scales with how long each instance runs. The choices span general-purpose and compute-balanced instance families in medium, large, and xlarge sizes. Larger sizes give more CPU and memory per hour. You select the instance that matches the compute your Data Mediation workload needs, then pay only for the hours used. No upfront commitment applies under this usage model.
Top-of-mind questions for buyers
What differences separate the general-purpose and compute-balanced instance dimensions offered here?
The t3 and t3a families are burstable general-purpose instances, suited to workloads with variable CPU demand. The m5 and m6i families provide steadier CPU-to-memory balance for consistent compute. Within each family, medium, large, and xlarge sizes scale CPU and memory upward. You match the instance to your Data Mediation workload's steadiness and size.
Am I charged when an instance is stopped or paused?
Software charges accrue per running instance-hour under this usage model. A fully stopped instance stops accruing hourly software charges. Underlying AWS resources, such as attached storage, may still incur separate AWS fees while the instance is stopped. The software licence meters only running time.
Does the platform run inside my own environment, and does that affect how I am billed?
The runtime deploys inside customer-controlled environments in your data path. Billing still follows the hourly instance model you select on Marketplace. You pay for the EC2 instance-hours the runtime consumes. Retaining control over data, systems, and actions does not change the per-hour metering.
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
This is a security and platform release of the Composable Agentic Platform (CAP) Console on Red Hat Enterprise Linux 10.2 (Coughlan). The embedded Jetty server runtime moves from 12.1.10 to 12.1.13, closing three published vulnerabilities; the operating system baseline moves from Red Hat Enterprise Linux 10.1 to 10.2; and the Console, the shared rules libraries, and the CAP Agent engine align at build 30110 - the platform now reports 12.1.13 B30110 throughout, and the CAP version number continues to track the embedded Jetty version. For deployments coming from the previous AMI, this image also carries the two intervening maintenance rounds: the build 30100 audit events API (paged query, live event stream, and verifiable evidence export) and the build 30090 agent runtime improvement (rules engines now flush buffered work on a graceful server stop). Local logon remains the default and sign-in behaviour is unchanged. All existing rulesets, extensions, and TCL scripts continue to work unchanged.
Security:
Embedded Jetty 12.1.13 - This release closes CVE-2026-19203 (a specially crafted HTTP/1.1 chunked request could cause Jetty and an intermediary proxy to interpret different request boundaries - the finding most relevant to deployments behind a load balancer or CDN), CVE-2026-12611 (HTTP/2 requests could leave blocking writes permanently blocked, exhausting server threads) and CVE-2026-19204 (a WebSocket frame with an unknown opcode and a very large declared payload could force a large memory allocation). HTTP/2 and WebSocket are not enabled in this image, so the second and third are closed as defence in depth. The update also carries the intervening Jetty maintenance fixes, including a memory usage regression present since 12.1.8 and more efficient idle-timeout handling under concurrent load. There are no breaking changes in the Jetty 12.1.11 to 12.1.13 range, and a healthy launch continues to log zero WARN, zero ERROR.
Operating system baseline updated - The AMI is built on Red Hat's current RHEL 10.2 image, and the base operating system packages are brought fully current at image build time.
Audit and evidence (carried from build 30100):
Audit events API - The Console exposes the compliance-capture evidence store through its control-plane API: GET /api/v1/audit-events pages an agent's captured audit records (time window filters, opaque continuation cursor, newest-first latest=N reads for dashboards), and GET /api/v1/audit-events/stream delivers a live tail as server-sent events. Reads go to the agent's own evidence store over the Console's existing per-agent management channel - the Console holds no object store credentials - and require the same per-agent trace credential as the agent log viewer.
Verifiable evidence export - GET /api/v1/audit-events/export streams a verifiable evidence bundle for a date window and optionally one conversation: byte-identical evidence segments, their chain manifests (including manifests kept for retention-pruned segments, which bridge the hash chain across the hole), an index of matching records, the format contract, and a bundle manifest carrying the SHA-256 of every file. A standalone offline verifier, downloadable from the Console, proves file integrity and unbroken chain continuity from the bundle alone, air-gapped, with no CAP software installed.
Evidence access is itself evidenced - Every audit event read, live stream session, and evidence export is recorded in the Console audit log under new Read and Export action types, attributed to the user and source address. The AI Control Plane page includes the Audit and Evidence section: newest records per agent, live tail, and one-click bundle export. The OpenAPI contract at /api/v1/openapi.yaml documents all operations.
Requires Base Rules build 30100 or later on each agent for the read capability; agents on earlier builds report no events and are otherwise unaffected.
Agent runtime (carried from build 30090):
Graceful-stop flush - The Agent runtime flushes every rules engine on a graceful server stop. Rule cleanup previously ran only when a configuration was redeployed; it now also runs when the web application stops, so a server restart or container recycle completes buffered work instead of abandoning it. Extensions that buffer data benefit immediately - in particular the Guardrail Pack compliance capture store seals its open evidence segment and delivers pending uploads and SIEM forwards during shutdown.
Platform updates:
Console, RulesBase, and Agent engine at build 30110 - All three components move to build 30110 for this release, aligned with the embedded Jetty version. Rule execution semantics are unchanged.
Dependency review - Jetty 12.1.10 to 12.1.13 is the only bundled library change since the previous AMI. The Nimbus JOSE+JWT library introduced with the previous release and all other bundled dependency versions are unchanged (HttpClient5 5.6.4, HttpCore5 5.4.3, Log4j API 2.25.5, Derby 10.17.1.0, and the rest). Red Hat Enterprise Linux base OS packages are upgraded to current at image build time.
RHEL 10.2 + JDK 21 LTS - The AMI moves to the Red Hat Enterprise Linux 10.2 (Coughlan) base; the JDK 21 LTS foundation, systemd cap-console service, first-boot cap-init credential initialisation, and pre-installed AWS Systems Manager agent are unchanged.
Reproducible AMI build - The AMI is produced by the same auditable EC2 Image Builder pipeline (triggered from GitHub Actions OIDC) used for prior releases, baked from the identical CI-built Console distribution published to all other channels.
Upgrade notes:
The embedded Jetty update cannot be delivered as an in-place Console update: in-place updates replace the Console web application only and never change the server runtime. For that reason there is deliberately no in-place Console package for this release on the TomorrowX update server - a Console reporting 12.1.13 over an older runtime would misstate the deployment's security posture. Existing installations take the runtime update by redeploying on this AMI, or by the distribution refresh procedure - see Updating Between V12 Releases under Installation and Configuration in the product documentation.
Agents do not self-update. After updating the platform, replace magic-12.0.jar in each agent's lib or WEB-INF/lib with the build 30110 jar and restart, then confirm the agent reports 12.1.13 B30110 in the Console. Deployments coming from the previous AMI need this step to gain the graceful-stop flush as well: their agents are on build 30080, which predates it.
Updated extensions are on the update server: Base Rules build 30110 and the Built-in Proxy at 12.1.13, which refreshes the Jetty libraries used by the proxy machinery inside forwarding agents. Apply them through the normal extension deployment process and redeploy your agents.
As with all new programming languages, the Hello, World! program generally is a computer program that outputs or displays the message Hello, World. Such a program is very simple in most programming languages and is often used to illustrate the basic syntax of a programming language. It is often the first program written by people learning to code.
Support is delivered through partners, with TomorrowX providing platform support and specialist advisory capability where applicable. Support levels scale by license tier and are confirmed during onboarding. The customer retains control of infrastructure and networking within their AWS environment. For platform support requests, please visit: - https://tomorrowx.dev/get-help/
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.