Back to the registry
Agent passport

Autonoma PLATFORM: Autonomous Software Lifecycle Platform (BYOC)

Autonoma · Cybersecurity & IT

Partial captureNo attestation published

Certification per AWS Marketplace.

Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownSaaS
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

RUNS IN YOUR AWS ACCOUNT

Autonoma PLATFORM is not hosted SaaS. Subscribing gives you a CloudFormation template that you deploy through AWS Marketplace Quick Launch into your own AWS account, in the single AWS Region you choose. The stack creates a dedicated VPC and provisions 22 AWS Fargate services with their own PostgreSQL database, Redis cache and EFS file system. Your source code, findings and telemetry stay inside that VPC. Autonoma holds no credential to your account and cannot reach any resource in it. Running these resources incurs AWS charges billed to you, separately from this subscription.

Show the rest of the publisher’s description (26 more lines)

THE AUTONOMA PRODUCT FAMILY

Autonoma PLATFORM is the complete product. BUILD, OPERATE and SECURE are also sold separately; PLATFORM bundles all three with an orchestrator for cross-capability workflows, and is the only product that scores technical debt and produces modernization plans.

FIFTEEN AGENTS ACROSS THREE DOMAINS

BUILD domain (7 agents): Requirement AI, Planner AI, Architect AI, Coder AI, Tester AI, plus shared Review AI and Debug AI. Requirements analysis through code generation, testing and review.

OPERATE domain (8 agents): Deploy AI, Maintain AI, Observe AI, Incident AI, Capacity AI, Backup AI, plus shared Review AI and Debug AI. Deployment, monitoring, incident response, scaling and recovery.

SECURE domain (2 agents): Security AI scans containers, dependencies and code for vulnerabilities. ThreatHunter AI provides threat detection using indicator matching and anomaly detection.

TECHNICAL DEBT AND MODERNIZATION

PLATFORM scores technical debt across five weighted dimensions: complexity, coupling, code smells, dependencies and test gap. Each dimension reports its own provenance, and a dimension with no data is reported as unavailable rather than scored as clean.

The test-gap dimension reads the coverage report your build already produces, in Go coverprofile, LCOV or Cobertura format. Autonoma does not execute your test suite; where no report exists, the dimension says so.

Modernization scanning maps your current architecture across 12 languages, identifies coupling and cycles, and produces a sequenced plan for addressing them. Architect AI then reviews that plan and advises which seam to cut first, given what the packages actually do. This is advisory: PLATFORM produces the plan and the evidence behind it, and does not perform the refactor.

CROSS-CAPABILITY WORKFLOWS

The orchestrator coordinates agents across all three domains.

Full lifecycle: requirements flow through BUILD agents for implementation, SECURE scans the result, OPERATE deploys and monitors it.

Incident-driven development: OPERATE detects an issue and performs root cause analysis, BUILD agents implement the fix, SECURE validates it before deployment.

Security-driven refactoring: SECURE identifies vulnerabilities, BUILD agents implement remediations, OPERATE deploys them with rollback.

ORCHESTRATION AND CONTROL

The orchestrator coordinates the per-domain orchestrators and RIGOR execution, and a shared knowledge graph carries learning between capabilities.

Autonomy is graduated, not absolute. Agents run at a configurable autonomy level, from shadow mode through to autonomous execution. Every agent decision carries provenance recording what evidence produced it, consequential actions are gated for approval, and third-party dependency installation is blocked behind a security scan and an explicit acknowledgement. Actions are auditable and reversible.

INTELLIGENCE TIERS

CORE is included at no extra cost, with baseline reasoning across all fifteen agents. The PRO add-on upgrades to a stronger reasoning model with cross-project pattern recognition. The ULTRA add-on provides the most advanced reasoning model with industry-wide shared intelligence.

INCLUDED USAGE

Each developer receives, per month: 60 combined builds and deploys, 30 RIGOR cycles, 10 combined monitored services and incident responses, and 500 security scans. These are pooled allocations - builds and deploys draw on a single pool, and monitoring and incident response draw on another. Agent compute hours are metered from the first hour.

WHAT THE STACK USES

Amazon ECS on AWS Fargate, Amazon RDS for PostgreSQL, Amazon ElastiCache for Redis, Amazon EFS, AWS Secrets Manager, Amazon CloudWatch Logs, AWS X-Ray, AWS Cloud Map and an Application Load Balancer, all created in your account by the stack. Optionally, install the Autonoma GitHub App to relay repository events to your deployment over a signed webhook you can verify.

AWS SERVICES THE AGENTS READ AND ACT ON

OPERATE agents call AWS APIs directly, using the deployment's own role in your account: CloudWatch metrics and logs, X-Ray traces, ECS, ECR, EC2 Auto Scaling, Cost Explorer, Systems Manager, Certificate Manager and RDS snapshots. SECURE agents run Trivy, Grype and Syft. BUILD agents operate on your source code rather than on AWS APIs.

Highlights

Highlighted by the publisher on AWS Marketplace.

Fifteen autonomous AI agents across three domains: BUILD (7) for requirements, architecture, coding, testing, review. OPERATE (8) for deployment, monitoring, incidents, scaling, backup. SECURE (2) for vulnerability scanning and threat hunting. Shared Review AI and Debug AI bridge development and operations seamlessly.

MetaOrchestrator enables cross-capability workflows: Full SDLC Automation from idea to production, Incident Driven Development with automatic fixes, Security Driven Refactoring with safe rollbacks. Native AWS integration with CodePipeline, CloudWatch, ECS, EKS, RDS, ECR, and Security Hub.

Combined usage allocations per developer: 60 builds, 30 RIGOR cycles, 12 deploys, 10 monitored services, 100 incident responses, 500 scans, and 5 compliance frameworks per month. Cross-agent knowledge graph shares learnings between capabilities for continuous improvement.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Plans and pricing as listed

5 listed
Additional Builds and Deploys (Overage)
  • Units
$0.10
Additional Monitoring and Incidents (Overage)
  • Units
$0.50
Additional Security Scans (Overage)
  • Units
$0.20
Additional RIGOR Cycles (Overage)
  • Units
$0.20
Agent Compute Hours (Overage)
  • Units
$0.10

Refund terms

As stated by the publisher on AWS Marketplace.

Full refund within 30 days of initial purchase, no questions asked. After 30 days, pro-rated refunds based on unused contract period. USAGE CHARGES: Refunded if metering errors confirmed, pro rated credits for service quality issues, full refund for platform-caused erroneous usage. NON REFUNDABLE: Consumed usage (builds, deployments, RIGOR cycles, agent hours), successfully completed services, charges greater than 90 days old.

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource
CustomEulaCustomEulaSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
5 plans listed
Delivery
SaaS
Email: support@theautonoma.io Support: https://www.theautonoma.io/contact
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.