What is AWS Continuum?
AWS Continuum is a security platform that, according to AWS, discovers, prioritises, validates, and remediates security risks across the software lifecycle. AWS describes it as combining agentic AI capabilities with human-defined guardrails, summarised as “security at machine speed”.
AWS announced AWS Continuum on 17 June 2026 at the AWS Summit in New York. Its capability areas differ in maturity: penetration testing is generally available, code vulnerabilities is in a gated preview, and code scanning and threat modeling are preview features.
Core Features
- Code vulnerabilities (gated preview): Addresses the complete vulnerability lifecycle, using multiple AI models to reason about the environment, confirm real issues, and drive toward fixes
- Penetration testing (generally available): On-demand pen testing that, per AWS, completes in hours rather than days and delivers validated vulnerabilities with reproducible proof and ready-to-implement remediation
- Code scanning (preview): Deep security analysis against compliance requirements, exploit patterns, and threat vectors with actionable guidance
- Threat modeling (preview): Generates context-aware STRIDE threat models based on design documents or codebases
- Prioritisation by business impact: Findings are prioritised by business impact, exploitability is proven, and the fix is driven through your own process
- Human approval: Human approval initiates most actions; you define which actions the system may execute independently
Typical Use Cases
Managing vulnerability volume: Instead of every finding, teams work on the ones whose exploitability is proven and whose business impact is high.
Penetration testing at development pace: On-demand tests can be scheduled more frequently than classic externally commissioned assessments.
Security analysis in the development process: Code scanning checks against compliance requirements, exploit patterns, and threat vectors.
Threat modeling without workshop overhead: Threat modeling produces STRIDE models from design documents or the codebase.
Benefits
- Validated exploitability instead of plain finding lists
- Penetration testing with reproducible proof and concrete remediation guidance
- Prioritisation based on business impact
- Remediation routed into your team’s existing process
- The scope of autonomous actions remains defined by you
Integration with innFactory
As an AWS Reseller, innFactory supports you with AWS Continuum: assessing the capability areas and their respective maturity, placing them in your existing security toolchain, defining approval rules and guardrails, and connecting the platform to your remediation processes. Because several capability areas are in preview, we review the current state in the official documentation with you before any production use.
Typical Use Cases
Frequently Asked Questions
What is AWS Continuum?
AWS Continuum is a security platform that, according to AWS, discovers, prioritises, validates, and remediates security risks across the software lifecycle. AWS describes it as combining agentic AI capabilities with human-defined guardrails. AWS announced the platform on 17 June 2026 at the AWS Summit in New York.
Which capability areas does AWS Continuum cover?
AWS names four areas: code vulnerabilities, penetration testing, code scanning, and threat modeling. The areas differ in maturity.
Which capability is already generally available?
Per the product page, penetration testing is generally available and accessible through the AWS console. AWS describes on-demand pen testing that completes in hours rather than days and delivers validated vulnerabilities with reproducible proof and ready-to-implement remediation.
How do I get access to the preview capabilities?
Per AWS, code vulnerabilities is in a gated preview with design partners; access is requested through an interest form. AWS lists code scanning and threat modeling as preview features.
What happens to AWS Security Agent?
Per the AWS Summit New York 2026 announcements, AWS Security Agent is now part of AWS Continuum, with threat modeling available in preview.
How much control do my teams keep?
AWS states that human approval initiates most actions. You define which actions the system can execute independently.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of AWS (official documentation). This page does not represent an offer by AWS.