Deploys into your own AWS account - your source code, scan findings and vulnerability data never leave your VPC. Findings are never sent to Autonoma, and Autonoma holds no credential to your account. security-ai scans source, dependencies and container images to identify vulnerabilities before they reach production; threathunter-ai enriches findings with CVE intelligence and hunts for active threats; an orchestrator sequences them. Both run the RIGOR framework - Research, Inspect, Generate, Optimize, Review - so every finding carries provenance and every remediation is gated, auditable and reversible. One CloudFormation stack provisions 9 AWS Fargate services with their own PostgreSQL, Redis and EFS, in the region you choose.
Autonoma SECURE is not hosted SaaS. Subscribing gives you a CloudFormation template that you deploy through AWS Marketplace Quick Launch into your own AWS account, in the single AWS Region you choose. The stack creates a dedicated VPC and provisions 9 AWS Fargate services with their own PostgreSQL database, Redis cache and EFS file system. Your source code, scan findings and vulnerability data stay inside that VPC. Autonoma holds no credential to your account and cannot reach any resource in it. Running these resources incurs AWS charges billed to you, separately from this subscription.
THE AUTONOMA PRODUCT FAMILY
Autonoma SECURE is one of four products. BUILD provides autonomous development with agents that design, code, test and review. OPERATE delivers autonomous operations with monitoring, incident response and remediation. PLATFORM combines all capabilities with cross-capability orchestration, and adds technical-debt scoring and modernization planning. Each works standalone or together.
TWO SPECIALIZED AI AGENTS
Security AI performs vulnerability analysis across several dimensions. Container scanning examines base images and layers for known CVEs, misconfigurations and compliance violations. Dependency analysis traverses your dependency tree to identify vulnerable packages, outdated libraries and license issues. Code analysis detects security antipatterns, injection flaws, authentication weaknesses and OWASP Top 10 issues in source across 12 languages: C, C++, C#, Go, Java, JavaScript, Kotlin, PHP, Python, Ruby, Rust and TypeScript.
ThreatHunter AI provides threat detection and response. It monitors for indicators of compromise, performs behavioral analysis to detect anomalous patterns, correlates security events and generates attack path analysis. Anomaly detection identifies threats that signature matching alone would miss.
Detection is signature and pattern based. It detects what its rules and tables cover; a framework or datastore outside those tables is not detected, and every report names what was analyzed and what was not.
VULNERABILITY MANAGEMENT
Findings are correlated across scan types to identify attack chains. Severity assessment considers exploitability, attack surface exposure and data sensitivity, so prioritization reflects actual risk rather than raw CVSS score. Remediation guidance proposes specific code changes, version upgrades and configuration fixes for your stack.
Remediation is proposed, not applied unattended. Patches are validated before they are offered, dependency installation during validation is gated behind a security scan and an explicit acknowledgement, and every action is auditable and reversible.
CONTINUOUS SECURITY
Scans run against your repositories on demand and on a schedule, so newly disclosed vulnerabilities are caught in code that has not changed. Install the Autonoma GitHub App and repository events reach your deployment over a signed webhook, so pull requests are scanned as they open.
COMPLIANCE AND REPORTING
Security AI maps findings to regulatory frameworks including SOC 2, HIPAA, PCI-DSS and ISO 27001, and generates evidence for them. Audit trails capture scanning activity, findings and remediation actions. Because the deployment runs in your account, that evidence and those findings remain in your control.
INTELLIGENCE TIERS
CORE is included at no extra cost, with container scanning for CVEs, infrastructure-as-code misconfigurations and secret detection. The PRO add-on upgrades to a stronger reasoning model and adds dependency scanning with exploit analysis, assisted remediation and cross-project pattern recognition. The ULTRA add-on provides the most advanced reasoning model with static application security testing across all 12 supported languages and industry-wide shared intelligence.
INCLUDED USAGE
Each developer receives 500 security scans and 5 compliance framework checks per month, at every tier. Agent compute hours are metered from the first hour.
WHAT THE STACK USES
Amazon ECS on AWS Fargate, Amazon RDS for PostgreSQL, Amazon ElastiCache for Redis, Amazon EFS, AWS Secrets Manager, Amazon CloudWatch Logs, AWS X-Ray, AWS Cloud Map and an Application Load Balancer, all created in your account by the stack. Optionally, install the Autonoma GitHub App to relay repository events to your deployment over a signed webhook you can verify.
SCANNING TOOLCHAIN
Container and dependency scanning runs Trivy, Grype and Syft inside your account, against the images and lockfiles you point them at. Static analysis of source runs in-process across the 12 supported languages. Findings are written to the PostgreSQL database this stack creates and stay in your account.
Highlights
Two autonomous security agents powered by the RIGOR framework. Security AI scans containers, dependencies, and code for CVEs, misconfigurations, and OWASP Top 10 issues. ThreatHunter AI proactively hunts threats using IOC matching, ML-based anomaly detection, and attack path analysis to catch what signature-based systems miss.
Shift security left with autonomous scanning across your SDLC. Pre-commit hooks, PR scanning, and runtime monitoring provide continuous protection. Native AWS integration with ECR, GuardDuty, Security Hub, and IAM Access Analyzer enables comprehensive cloud security posture management.
Intelligent vulnerability management prioritizes findings by exploitability and business impact rather than raw CVSS scores. Automated remediation guidance provides specific code changes, version upgrades, and configuration fixes. Compliance reporting for SOC 2, HIPAA, PCI DSS, and ISO 27001.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
Startup tier (1-5 developers). Select the range matching your team size. Includes Security AI and ThreatHunter AI agents for vulnerability scanning and threat detection per developer/month.
$445.00
02. PRO Intelligence Add-On (1-5 devs)
PRO Intelligence upgrade for 1-5 developers. Smarter reasoning model with cross-project pattern recognition. Must match your base tier seat range.
$175.00
03. ULTRA Intelligence Add-On (1-5 devs)
ULTRA Intelligence upgrade for 1-5 developers. Most advanced reasoning model with industry-wide shared intelligence pool. Must match your base tier seat range.
$325.00
04. SECURE Startup: 6-10 Developers
Startup tier (6-10 developers). Select the range matching your team size. Includes Security AI and ThreatHunter AI agents for vulnerability scanning and threat detection per developer/month.
$890.00
05. PRO Intelligence Add-On (6-10 devs)
PRO Intelligence upgrade for 6-10 developers. Smarter reasoning model with cross-project pattern recognition. Must match your base tier seat range.
$350.00
06. ULTRA Intelligence Add-On (6-10 devs)
ULTRA Intelligence upgrade for 6-10 developers. Most advanced reasoning model with industry-wide shared intelligence pool. Must match your base tier seat range.
$650.00
07. SECURE Startup: 11-15 Developers
Startup tier (11-15 developers). Select the range matching your team size. Includes Security AI and ThreatHunter AI agents for vulnerability scanning and threat detection per developer/month.
$1,335.00
08. PRO Intelligence Add-On (11-15 devs)
PRO Intelligence upgrade for 11-15 developers. Smarter reasoning model with cross-project pattern recognition. Must match your base tier seat range.
$525.00
09. ULTRA Intelligence Add-On (11-15 devs)
ULTRA Intelligence upgrade for 11-15 developers. Most advanced reasoning model with industry-wide shared intelligence pool. Must match your base tier seat range.
$975.00
10. SECURE Startup: 16-19 Developers
Startup tier (16-19 developers). Select the range matching your team size. Includes Security AI and ThreatHunter AI agents for vulnerability scanning and threat detection per developer/month.
You buy this platform per developer, per month, under a contract deployed in your own AWS account. Pick the base SECURE tier that matches your team size. Ranges span from 1-5 developers up to 400-500, grouped into Startup, Growth, Scale, and Enterprise bands. Each base tier includes vulnerability scanning and threat detection. You can add a PRO or ULTRA Intelligence upgrade, which must match your base seat range. Three overage dimensions bill any usage beyond included quotas: extra security scans, extra compliance checks, and additional agent compute hours.
Top-of-mind questions for buyers
What counts as one developer for billing purposes?
A developer is a unique human account that can invoke the agents. Billing meters active seats per cycle. Seats with no activity for 30 days are automatically dropped from the billable count, so you are not charged for dormant accounts.
What happens if I exceed the included security scans or compliance checks?
You keep working without a hard cut-off. Any usage past your included quota bills at the overage rate for that dimension. Since agents run in your own AWS account, there is no hard cap. Extra security scans, compliance checks, and agent compute hours each bill separately.
How do the base tier and Intelligence Add-On charges combine on my bill?
You pay the base SECURE tier per developer for your seat range. If you add a PRO or ULTRA Intelligence upgrade, it must match that same seat range and bills on top of the base tier. Both charges apply together for every developer.
www.theautonoma.io
Helpful?
Vendor refund policy
Full refund within 30 days of initial purchase, no questions asked. After 30 days, pro-rated refunds based on unused contract period. USAGE CHARGES: Refunded if metering errors confirmed, pro rated credits for service quality issues, full refund for platform-caused erroneous usage. NON REFUNDABLE: Consumed usage (builds, deployments, RIGOR cycles, agent hours), successfully completed services, charges greater than 90 days old.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Additional details
Usage instructions
Deploy Autonoma SECURE manually
Prefer the guided path? Use Quick Launch on the Configure and launch page and skip
this page entirely. It fills in your credentials for you.
These instructions are for deploying the same CloudFormation template yourself.
Before you start
You need an active AWS Marketplace subscription to Autonoma SECURE, and permission to
create IAM roles, VPCs, RDS, ElastiCache, EFS and ECS services in your AWS account.
You need the API key, the LLM proxy token and the metering token. Quick Launch supplies
these automatically. A manual deployment does not, so you provide them below.
CustomerId must be 1 to 19 characters, lowercase letters, digits and hyphens, starting
with a letter or digit. It becomes the name prefix for every resource the stack creates.
Every other parameter has a default. The ones you are most likely to change are
VpcCidr, DbInstanceClass, AgentDesiredCount, DbBackupRetention and AlertEmail.
The Autonoma SECURE data plane runs entirely in your account: orchestrator-ai, security-ai and threathunter-ai, plus the
supporting services (NATS, OpenTelemetry collector, LSP, knowledge graph, scan worker,
API gateway). That is 9 services on AWS Fargate in a dedicated VPC with its own
PostgreSQL, Redis and EFS.
Your source code, scan findings and vulnerability data stay inside that VPC. Autonoma holds no credential to your account.
Running these AWS resources incurs AWS charges billed to you, separately from your AWS
Marketplace subscription.
The database is snapshotted rather than discarded, by design. Deleting the stack leaves a
final RDS snapshot in your account, which survives the stack and continues to incur
storage charges until you delete it yourself.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Autonomous software development platform with five specialized AI agents and intelligent orchestration that transform requirements into production ready code. Our agents work together using the RIGOR reasoning framework to analyze requirements, plan projects, design architecture, generate code, and create comprehensive tests. Reduce development time by 60% while maintaining enterprise code quality standards. Autonoma BUILD is part of the Autonoma product family. Combine with Autonoma OPERATE for deployment automation and self healing infrastructure, add Autonoma SECURE for vulnerability scanning, or choose Autonoma PLATFORM for complete cross capability orchestration across your entire software lifecycle.
The complete autonomous software lifecycle platform combining BUILD, OPERATE, and SECURE capabilities through fifteen specialized AI agents coordinated by the MetaOrchestrator. BUILD agents (7) handle requirements, architecture, coding, testing, and review. OPERATE agents (8) manage deployments, monitoring, incidents, scaling, and disaster recovery. SECURE agents (2) scan for vulnerabilities and hunt threats using IOC matching and ML-based detection. The MetaOrchestrator enables cross-capability workflows impossible with individual products: Full SDLC Automation from idea to production, Incident Driven Development with automatic fixes, and Security Driven Refactoring with safe rollbacks. Built on the RIGOR framework (Research, Inspect, Generate, Optimize, Review) with shared Review AI and Debug AI bridging development and operations. Native AWS integration with CodePipeline, CloudWatch, ECS, Security Hub, and more.
Autonomous operations platform with six specialized AI agents and intelligent orchestration that detect, diagnose, and resolve production issues without human intervention. Our agents work 24/7 using the RIGOR reasoning framework to predict failures, perform root cause analysis, implement fixes, and deploy with automatic rollback. Transform your operations from reactive firefighting to proactive self healing infrastructure that maintains up to 99.99% uptime. Autonoma OPERATE is part of the Autonoma product family. Combine with Autonoma BUILD for full SDLC automation, add Autonoma SECURE for vulnerability scanning and patching, or choose Autonoma PLATFORM for complete cross capability orchestration across your entire software lifecycle.
Deploys into your own AWS account - your source code, build artefacts and telemetry never leave your VPC, and Autonoma holds no credential to your account. Seven specialized AI agents and an orchestrator carry work from requirement to reviewed, tested code: req-ai captures intent, planner-ai sequences the work, architect-ai designs the change, coder-ai implements it, tester-ai builds the suites, debug-ai isolates failures, and review-ai reviews across 12 languages. Every agent runs the RIGOR framework - Research, Inspect, Generate, Optimize, Review - so each decision carries provenance and is gated, auditable and reversible. One CloudFormation stack provisions 14 AWS Fargate services with their own PostgreSQL, Redis and EFS, in the region you choose.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.