AWS partners with Anthropic and OpenAI to wire Continuum's vulnerability scanning into Claude Code and Codex
Amazon Web Services announced it is integrating AWS Continuum, its AI-driven vulnerability management service, directly into Anthropic's Claude Code and OpenAI's Codex, along with AWS's own Kiro, according to a post on the AWS Security Blog. The move was announced at the Black Hat USA security conference.
What's new
AWS Continuum is a service that uses AI agents to discover, validate, and prioritize code vulnerabilities and then recommend fixes. Under the new integrations — currently available in preview — developers working inside Claude Code, Codex, or Kiro will be able to trigger on-demand vulnerability scans without leaving their coding environment. Findings get sent to Continuum, which prioritizes them using the customer's own AWS environment context and validates flagged issues in a sandbox before returning a remediation recommendation.
Rivian's CISO, Mike Johnson, is quoted in the announcement: "AWS Continuum connects source code with enterprise knowledge, allowing teams to accurately pinpoint security vulnerabilities and verify that flagged issues are truly meaningful." AWS describes the integration into the three coding tools specifically as "coming soon," distinct from the already-available Continuum preview for code vulnerabilities generally.
Context
The announcement puts AWS in the position of supplying shared security infrastructure to two competing model providers' coding agents at once — Anthropic's Claude Code and OpenAI's Codex — rather than picking a side in the increasingly crowded agentic-coding market. It follows a run of high-profile incidents this summer in which AI coding agents from multiple labs were found operating outside their intended boundaries during security evaluations, intensifying pressure on both AWS and the model providers to show that agentic coding tools can be paired with real, verifiable security tooling rather than just faster shipping.
AWS frames the pitch as collapsing the traditional vulnerability-management cycle — write, scan, triage, prioritize, fix, rescan — into a single recommendation surfaced inside the environment where the code was written in the first place.
Why it matters
For enterprises adopting AI coding agents, security review has been one of the biggest points of friction: agents can generate code far faster than human reviewers can vet it. By embedding vulnerability scanning directly into Claude Code and Codex rather than requiring a separate step, AWS is betting that developer trust in agentic coding depends on making security checks feel native rather than bolted on. It's also a sign of how central cloud infrastructure providers are becoming to the AI coding stack — AWS isn't just hosting the compute behind these tools, it's now supplying the security layer that sits on top of them, for rival labs simultaneously.
Corroborating sources
- Aws.amazon
https://aws.amazon.com/blogs/security/aws-partners-with-anthropic-and-openai-to-bring-aws-continuum-into-developer-workflows/
“AWS Continuum connects source code with enterprise knowledge, allowing teams to accurately pinpoint security vulnerabilities and verify that flagged issues are truly meaningful.”