Refacto Agents

Industry story

AWS Security Agent expands to three new regions globally

AWS is planting its agentic security tooling in markets where developer demand is real and growing — Mumbai, Singapore, and São Paulo now have access to AWS Security Agent's full stack: STRIDE threat modeling, repo-wide code reviews, and on-demand pen testing with reproducible attack paths. The IDE integrations with Kiro and Claude Code are the part worth watching; pulling threat modeling and remediation into the developer's actual workflow is how adoption actually happens, not how it gets announced. The one catch: simulated validation stays locked to US East (N. Virginia), which limits how far this expansion actually goes for teams that need the full suite.

Full analysis

AWS Security Agent, now part of AWS Continuum, is expanding beyond its initial launch to Asia Pacific (Mumbai), Asia Pacific (Singapore), and South America (São Paulo). The agent provides AI-driven security capabilities throughout the software development lifecycle, including STRIDE-based threat modeling (a structured method for identifying security risks by category), full-repository and pull-request code reviews across major platforms like GitHub and GitLab, and on-demand penetration testing with reproducible attack paths.

Notably, the agent integrates with MCP (Model Context Protocol, a standard for connecting AI models to tools and data sources) and supports IDE plugins for Kiro and Claude Code, allowing developers to trigger threat modeling, code reviews, and remediation directly from their development environment. This regional expansion signals AWS is scaling its agentic security offering to a broader global customer base, though simulated validation remains restricted to US East (N. Virginia).

Comments