View a markdown version of this page

Document history - AWS Security Agent

Document history

The following table describes some of the major updates and new features for the AWS Security Agents User Guide.

ChangeDescriptionDate

Revalidate penetration test findings

Added documentation for revalidating penetration test findings. You can select existing findings and re-test whether they are still exploitable, without running a full penetration test. Revalidation runs as a separate job and reports whether each finding is still active or resolved, without changing the original finding.

August 13, 2026

Maximum task hours for penetration tests and code reviews

Added documentation for setting a maximum task-hours limit when you create a penetration test or code review. When a run reaches the limit, AWS Security Agent stops it gracefully and keeps the findings discovered so far.

August 13, 2026

Pricing and billing

Added documentation for pricing and billing. This topic explains what accrues task hours, the unit AWS Security Agent bills for penetration testing. It covers why task hours differ from the duration of a run and where to find task hours. It also explains why service quotas are not spending limits. For more information, see Pricing and billing.

August 11, 2026

Email MFA for penetration testing credentials

Added documentation for email MFA. You can now enable email-based multi-factor authentication (MFA) for penetration testing credentials. When enabled, AWS Security Agent can complete logins for applications that send a one-time code or verification link by email. AWS Security Agent generates a unique forwarding address that you configure in your email provider.

August 6, 2026

Private connections general availability

Private connections are now generally available. This capability allows AWS Security Agent to connect to source control systems running in private networks using Amazon VPC Lattice, without exposing your systems to the public internet.

July 28, 2026

Private connections (preview)

Added documentation for private connections. This new capability allows AWS Security Agent to connect to source control systems running in private networks using Amazon VPC Lattice, without exposing your systems to the public internet.

June 16, 2026

Threat modeling (preview)

Added documentation for threat modeling. This new capability builds a threat model of your application from design documents (scope docs), source code (sources), or both. Scope docs are feature design documents that define the focus of the analysis, while source code provides context about your existing system. If you don’t provide scope docs, the agent generates a threat model from the source code alone. Each run produces a system overview and a set of threats classified by STRIDE category with severity ratings and recommendations.

June 8, 2026

Full repository code review (preview)

Added documentation for full repository code review. This new capability performs context-aware security analysis of your entire codebase and generates code remediation for findings.

May 12, 2026

Updated Region availability for finding remediation

Region availability for penetration test finding remediation in the AWS Security Agent web application has been updated.

April 16, 2026

Updated Region availability for enabling finding remediation

Region availability for enabling penetration test finding remediation in the AWS Management Console has been updated.

April 16, 2026

Customer managed key support

Added documentation for customer managed key (CMK) support. You can now specify a customer managed KMS key when creating Agent Spaces and integrations to encrypt your data with keys you control.

March 31, 2026

AWS managed policy updates

Added AWSSecurityAgentWebAppPolicy managed policy for the new TargetDomain and DesignReviewFeedback resource types.

March 31, 2026

AWS managed policy updates

Added AWSSecurityAgentWebAppPolicy managed policy for the new AgentSpace resource type and IAM action name changes.

February 9, 2026

AWS managed policy updates

Updated SecurityAgentWebAppAPIPolicy to allow customers to delete design reviews.

January 28, 2026

AWS managed policy updates

Updated SecurityAgentWebAppAPIPolicy to allow customers to start automated code remediation for security findings.

January 20, 2026

AWS managed policy updates

Updated to SecurityAgentWebAppAPIPolicy to allow customers to view images in the console.

December 5, 2025

AWS Security Agents initial release

Initial documentation for service launch

December 2, 2025