AWS Open Source Security
Committed to raising standards for the broader community
Overview
At AWS, security is our top priority. We work hard to make AWS the best place for customers to build and run open source software in the cloud. We are committed to raising the bar for open source security by developing key security-related technologies in collaboration with the community and by contributing code, resources, and talent to open source software.
We actively participate in open source foundations, trade associations, standard bodies, and regulatory organizations, with a goal of improving software supply chain security to benefit our customers and improve security posture across the industry.
Security frameworks and tools as open source
We work upstream and release security frameworks and tools as open source to improve security posture across the industry.
Featured AWS open source security projects
Some of the most popular open source developer tools, platforms, databases, and services on AWS are based on leading open source projects. Amazon-led projects of note include:
Snapchange
Snapchange started as an experiment by the Find and Fix (F2) open source security research team to explore the potential of using KVM in enabling snapshot fuzzing. It’s one of a number of tools and techniques used by the F2 team in its research efforts to enable a secure and trustworthy open source supply chain for AWS and its customers.

Cedar
Define permissions as easy-to-understand policies with Cedar, an open source language for access control built by using automated reasoning and differential testing.

Bottlerocket
AWS launched Bottlerocket, a Rust language-oriented Linux for containers, and the Amazon EC2 team uses Rust as the language of choice for new AWS Nitro System components.

Kani Rust Verifier Project
This is an open source project maintained by AWS that helps the verification of unsafe code blocks in Rust that may contain memory safety issues, leading to security concerns.

Firecracker
Written in Rust, Firecracker provides the open source virtualization technology that powers AWS Lambda and other serverless offerings.

Innovations from Open Source Security
Have Questions?
Connect with AWS Support
Contact Us »
Exploring security roles?
Apply today »
Want AWS Security updates?
Follow us on X »