Best Practices
In-depth guides and analysis on best practices from the Safeguard engineering team.
252 articles
What is Security by Obscurity
Security by obscurity means hiding a system instead of securing it. Here's why that bet fails, with real breaches, real CVEs, and what to build instead.
What is a Trust Store
Trust stores decide which signatures your systems believe. Here's how they work, why they matter for supply chain security, and how to audit them.
Build a Software Supply Chain Program in 90 Days
A pragmatic, phase-by-phase blueprint for standing up a credible software supply chain security program inside a single fiscal quarter without boiling the ocean.
What is Credential Rotation
Credential rotation limits how long a leaked API key, password, or token stays valid. Here's how it works, how often to do it, and why automation matters.
Security Code Review Best Practices
How to make code reviews an effective security checkpoint without turning every PR into a week-long security audit.
Container Image Hardening Checklist
A comprehensive checklist for hardening your container images, from base image selection to runtime protections, with practical Dockerfile examples.
The End-of-Year Dependency Audit Ritual
Most dependency audits get done in a panic after a CVE lands. A planned year-end audit is cheaper, more thorough, and produces a backlog you can actually work through in Q1.
Open Source Policy Template for Enterprises
A practical template for crafting an enterprise open-source usage policy that balances developer freedom with security and compliance requirements.
Shifting Left Without Slowing Down
How to integrate security earlier in the development lifecycle without turning your CI pipeline into a bottleneck that developers hate.
Secure Coding Practices: A Developer's Guide
Practical secure coding habits every developer should build, covering input validation, authentication, dependency management, and more.
Why Dependency Pinning Alone Is Not Enough
Pinning dependencies feels like a complete answer to supply chain risk. It is not — and the gap between pinning and real integrity matters more in 2022 than ever.
A First-Principles Guide to Artifact Signing in 2022
Artifact signing is having a moment, but most teams skip the fundamentals. Here is the first-principles case for why you sign, what you sign, and who verifies.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.