Back to the registry
Agent passport

Autonoma SECURE: Autonomous Software Lifecycle Platform (BYOC)

Autonoma · Cybersecurity & IT

Partial captureNo attestation published

Certification per AWS Marketplace.

Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownSaaS
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

RUNS IN YOUR AWS ACCOUNT

Autonoma SECURE is not hosted SaaS. Subscribing gives you a CloudFormation template that you deploy through AWS Marketplace Quick Launch into your own AWS account, in the single AWS Region you choose. The stack creates a dedicated VPC and provisions 9 AWS Fargate services with their own PostgreSQL database, Redis cache and EFS file system. Your source code, scan findings and vulnerability data stay inside that VPC. Autonoma holds no credential to your account and cannot reach any resource in it. Running these resources incurs AWS charges billed to you, separately from this subscription.

Show the rest of the publisher’s description (21 more lines)

THE AUTONOMA PRODUCT FAMILY

Autonoma SECURE is one of four products. BUILD provides autonomous development with agents that design, code, test and review. OPERATE delivers autonomous operations with monitoring, incident response and remediation. PLATFORM combines all capabilities with cross-capability orchestration, and adds technical-debt scoring and modernization planning. Each works standalone or together.

TWO SPECIALIZED AI AGENTS

Security AI performs vulnerability analysis across several dimensions. Container scanning examines base images and layers for known CVEs, misconfigurations and compliance violations. Dependency analysis traverses your dependency tree to identify vulnerable packages, outdated libraries and license issues. Code analysis detects security antipatterns, injection flaws, authentication weaknesses and OWASP Top 10 issues in source across 12 languages: C, C++, C#, Go, Java, JavaScript, Kotlin, PHP, Python, Ruby, Rust and TypeScript.

ThreatHunter AI provides threat detection and response. It monitors for indicators of compromise, performs behavioral analysis to detect anomalous patterns, correlates security events and generates attack path analysis. Anomaly detection identifies threats that signature matching alone would miss.

Detection is signature and pattern based. It detects what its rules and tables cover; a framework or datastore outside those tables is not detected, and every report names what was analyzed and what was not.

VULNERABILITY MANAGEMENT

Findings are correlated across scan types to identify attack chains. Severity assessment considers exploitability, attack surface exposure and data sensitivity, so prioritization reflects actual risk rather than raw CVSS score. Remediation guidance proposes specific code changes, version upgrades and configuration fixes for your stack.

Remediation is proposed, not applied unattended. Patches are validated before they are offered, dependency installation during validation is gated behind a security scan and an explicit acknowledgement, and every action is auditable and reversible.

CONTINUOUS SECURITY

Scans run against your repositories on demand and on a schedule, so newly disclosed vulnerabilities are caught in code that has not changed. Install the Autonoma GitHub App and repository events reach your deployment over a signed webhook, so pull requests are scanned as they open.

COMPLIANCE AND REPORTING

Security AI maps findings to regulatory frameworks including SOC 2, HIPAA, PCI-DSS and ISO 27001, and generates evidence for them. Audit trails capture scanning activity, findings and remediation actions. Because the deployment runs in your account, that evidence and those findings remain in your control.

INTELLIGENCE TIERS

CORE is included at no extra cost, with container scanning for CVEs, infrastructure-as-code misconfigurations and secret detection. The PRO add-on upgrades to a stronger reasoning model and adds dependency scanning with exploit analysis, assisted remediation and cross-project pattern recognition. The ULTRA add-on provides the most advanced reasoning model with static application security testing across all 12 supported languages and industry-wide shared intelligence.

INCLUDED USAGE

Each developer receives 500 security scans and 5 compliance framework checks per month, at every tier. Agent compute hours are metered from the first hour.

WHAT THE STACK USES

Amazon ECS on AWS Fargate, Amazon RDS for PostgreSQL, Amazon ElastiCache for Redis, Amazon EFS, AWS Secrets Manager, Amazon CloudWatch Logs, AWS X-Ray, AWS Cloud Map and an Application Load Balancer, all created in your account by the stack. Optionally, install the Autonoma GitHub App to relay repository events to your deployment over a signed webhook you can verify.

SCANNING TOOLCHAIN

Container and dependency scanning runs Trivy, Grype and Syft inside your account, against the images and lockfiles you point them at. Static analysis of source runs in-process across the 12 supported languages. Findings are written to the PostgreSQL database this stack creates and stay in your account.

Highlights

Highlighted by the publisher on AWS Marketplace.

Two autonomous security agents powered by the RIGOR framework. Security AI scans containers, dependencies, and code for CVEs, misconfigurations, and OWASP Top 10 issues. ThreatHunter AI proactively hunts threats using IOC matching, ML-based anomaly detection, and attack path analysis to catch what signature-based systems miss.

Shift security left with automated scanning across your SDLC. Pull requests are scanned automatically, and findings stay inside your VPC. Native AWS integration with ECR, GuardDuty, Security Hub and IAM Access Analyzer supports cloud security posture management alongside the agents' own scanning.

Intelligent vulnerability management prioritizes findings by exploitability and business impact rather than raw CVSS scores. Automated remediation guidance provides specific code changes, version upgrades, and configuration fixes. Compliance reporting for SOC 2, HIPAA, PCI DSS, and ISO 27001.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Plans and pricing as listed

3 listed
Additional Security Scans (Overage)
  • Units
$0.20
Additional Compliance Checks (Overage)
  • Units
$0.20
Agent Compute Hours (Overage)
  • Units
$0.10

Refund terms

As stated by the publisher on AWS Marketplace.

Full refund within 30 days of initial purchase, no questions asked. After 30 days, pro-rated refunds based on unused contract period. USAGE CHARGES: Refunded if metering errors confirmed, pro rated credits for service quality issues, full refund for platform-caused erroneous usage. NON REFUNDABLE: Consumed usage (builds, deployments, RIGOR cycles, agent hours), successfully completed services, charges greater than 90 days old.

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource
CustomEulaCustomEulaSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
3 plans listed
Delivery
SaaS
Email: support@theautonoma.io Support: https://www.theautonoma.io/contact
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.