In June 2026, AWS launched Continuum at AWS Summit NYC — an AI-native security platform that handles the full vulnerability lifecycle: discover, prioritize, validate, and remediate. In August 2026, they expanded it with integrations into Anthropic Claude Code and OpenAI Codex, bringing security intelligence directly into AI-assisted coding workflows.
This isn't another scanner. It's a security agent that reasons about your environment, confirms what's actually exploitable, and drives toward resolution — at machine speed, within guardrails you define.
#
What Is AWS Continuum?
AWS Continuum is an AI-powered security service that manages the full lifecycle of code vulnerabilities:
The key differentiator: Most scanners find vulnerabilities. Continuum validates whether they're actually exploitable in YOUR environment and context, then fixes them automatically.
#
The Problem Continuum Solves
Traditional AppSec workflow in 2026:
Continuum workflow:
#
AWS Continuum Components
- Continuum for Code Vulnerabilities
The core service — continuous security for your application code and dependencies:
Discovery: Scans code repositories, dependencies, and container images #
Prioritization: AI ranks by real-world exploitability, not just CVSS score #
Validation: Confirms vulnerabilities are reachable in your specific code paths #
Remediation: Generates fixes, creates pull requests, monitors deployment #
Verification: Re-tests after fix to confirm resolution
- AWS Security Agent
A frontier AI agent that performs on-demand penetration testing:
- Deploys specialized AI agents against your application
- Develops application context from documentation and credentials
- Executes multi-step attack scenarios (like a human pentester)
- Discovers complex vulnerabilities that static scanners miss
- Reports findings with full attack chain documentation
- Continuum + AI Coding Assistants (August 2026)
The latest expansion — security intelligence embedded directly in developer workflows:
Claude Code integration: Anthropic's AI assistant gets Continuum context when writing/reviewing code #
OpenAI Codex integration: Same security intelligence in Codex-powered workflows #
Kiro integration: AWS's own IDE incorporates Continuum findings
When AI generates code, Continuum validates it against known vulnerability patterns and your organization's security policies — before it reaches production.
#
How It Works: Architecture
#
Key Capabilities
Contextual Prioritization (Not Just CVSS)
Traditional scanners rank by CVSS score. A "Critical 9.8" vulnerability in a library function that's never called in your code is actually zero risk. Continuum uses AI to assess:
Reachability: Is the vulnerable code path actually reachable from your application's entry points? #
Exploitability: Given your environment (WAF rules, network config, IAM policies), can this be exploited? #
Blast radius: If exploited, what's the impact? (data exposure, lateral movement, privilege escalation) #
Business context: Is this in a production-critical service or a development tool?
Automated Validation
Continuum doesn't just report — it confirms. The Security Agent:
- Analyzes the vulnerability and your application architecture
- Develops a multi-step attack scenario
- Executes the attack in a controlled manner (like an automated pentester)
- Confirms whether the vulnerability is actually exploitable
- Documents the full attack chain for the development team
Automated Remediation
For confirmed vulnerabilities, Continuum generates fixes: #
Dependency updates: Creates PR updating vulnerable library to patched version #
Code fixes: Generates code patches for application-level vulnerabilities #
Configuration changes: Proposes infrastructure configuration remediations #
Staging validation: Tests the fix in a staging environment before promoting
All within guardrails you define — you control what gets auto-fixed vs what requires human approval.
#
Integration Points
Developer Workflow Integration
AWS Service Integration
| Integrates With | How | GitHub | PR comments, auto-fix PRs, repository scanning | CodeCommit | Same as GitHub (native AWS) | ECR | Container image vulnerability scanning | CodeBuild | Pipeline gate — block deploy on critical findings | Security Hub | Findings forwarded for unified security dashboard | CloudTrail | Audit trail of all Continuum actions | IAM | Scoped permissions for what Continuum can access/modify | Claude Code / Codex | Real-time security context during AI-assisted coding |
#
Continuum vs Existing Security Tools
| Tool | What It Does | Continuum Advantage | CodeGuru Security | SAST scanning | Continuum validates exploitability + auto-remediates | Inspector | CVE scanning for EC2/ECR/Lambda | Continuum adds AI reasoning about real-world risk | GuardDuty | Runtime threat detection | Continuum is proactive (pre-production), GuardDuty is reactive (runtime) | Security Hub | Aggregates findings | Continuum feeds INTO Security Hub with validated findings | Third-party SAST (Snyk, Checkmarx) | Code scanning | Continuum adds validation + auto-remediation + AI coding assistant integration |
Continuum doesn't replace these tools — it adds an AI reasoning layer on top. It can consume findings from Inspector, CodeGuru, and third-party scanners, then validate and remediate them.
#
Setting Up Continuum
Prerequisites
-
AWS account with Security Hub enabled
-
Code repository connected (GitHub, CodeCommit, GitLab)
-
IAM role for Continuum with appropriate permissions
-
Define guardrails (what can auto-remediate vs requires approval)
Guardrail Configuration
Scope Configuration
#
Security Agent: AI Pentesting
The Security Agent component is particularly interesting — it's essentially an AI penetration tester:
How Security Agent Works
Context gathering: Agent reads application documentation, API specs, architecture diagrams #
Threat modeling: AI identifies likely attack vectors based on application type #
Attack planning: Develops multi-step attack scenarios (SQLi → privilege escalation → data exfil) #
Execution: Runs attacks against your application (in controlled manner) #
Reporting: Documents successful attack chains with step-by-step reproduction
Use Cases
- Pre-release security review (before production deployment)
- Quarterly penetration testing (continuous, not annual)
-
Compliance validation (demonstrate attack testing for auditors)
-
Red team exercises (automated adversary simulation)
Security Considerations
- Agent operates within defined scope boundaries
- Credentials are scoped and time-limited
- All actions are logged to CloudTrail
- Blast radius controlled by IAM permissions
- Can be restricted to non-production environments
#
How Continuum Fits in DevSecOps
#
What Makes Continuum Different
Full lifecycle — not just scanning, but validation, prioritization, remediation, and verification #
AI-native — uses frontier models to reason about exploitability, not just pattern matching #
Context-aware — understands YOUR code, YOUR infrastructure, YOUR environment #
Developer-integrated — embedded in Claude Code, Codex, and Kiro (not a separate tool to check) #
Guardrail-controlled — you define what it can auto-fix and what requires human approval #
Validates, not just reports — confirms exploitability via Security Agent (AI pentesting)
#
Summary
AWS Continuum represents a shift from "scan and report" to "discover, validate, and fix":
Discovery: Continuous scanning of code, dependencies, containers, and infrastructure #
Prioritization: AI-powered, context-aware ranking (not just CVSS scores) #
Validation: Security Agent confirms exploitability via automated attack simulation #
Remediation: Generates fixes, creates PRs, validates in staging, all within guardrails #
Integration: Embedded in AI coding assistants (Claude Code, Codex) for shift-left security
For teams drowning in scanner noise — hundreds of findings, most not exploitable — Continuum's validation and auto-remediation capabilities represent a significant operational improvement. The integration with AI coding assistants means security feedback arrives while code is being written, not weeks later in a vulnerability report. *Alpesh Kumbhare is an AWS Architect at Atos, specializing in AWS security architecture and cloud infrastructure automation. Connect on *LinkedIn.