Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
FailSafe SWARM is an ACOST platform built for the full offensive security cycle: identify, prove and remediate. It continuously maps codebases, cloud environments, web applications, APIs and AI systems, then uses a council of frontier cyber models and FailSafe own GlassBreak LLM to generate attack hypotheses the way real attackers would.
SWARM builds structured threat models across architecture, trust boundaries and system invariants, then generates 50 to 80 prioritized attack hypotheses, deduplicates overlapping findings, and validates each issue with reproducible proof. Confirmed vulnerabilities are supported by evidence, exploit context, remediation guidance and audit-ready reporting.
Show the rest of the publisher’s description (1 more line)
Designed for security, engineering and compliance teams, SWARM can be re-run on high-risk triggers such as new pull requests, newly disclosed CVEs, newly exposed ports or changes in attack surface. This turns penetration testing from a periodic manual exercise into a continuous, autonomous security loop for modern applications, cloud infrastructure and AI-native systems.
Highlights
Highlighted by the publisher on AWS Marketplace.
ACOST platform that continuously identifies, proves and helps remediate exploitable vulnerabilities across code, cloud, web apps, APIs and AI systems
SWARM uses structured threat modeling, multi-model cyber agents and reproducible proof to reduce false positives and surface only validated security risks.
Re-runs on high-risk triggers such as new pull requests, newly disclosed CVEs, exposed ports or attack surface changes, with audit-ready reporting for security and compliance teams.
Preview
1 imageAgent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment
Plans and pricing as listed
3 listed- Requests
- Requests
- Requests
Refund terms
As stated by the publisher on AWS Marketplace.
Refund requests are reviewed case by case. Contact support@getfailsafe.com with your company name, AWS Marketplace order details and reason. Refunds may be considered for undelivered services, billing errors or inability to deliver. Completed scans, reports or services are generally non-refundable.
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

