Compliance
In-depth guides and analysis on compliance from the Safeguard engineering team.
302 articles
SBOM Compliance in 2025: Tracking Global Mandates and Deadlines
SBOM requirements are now embedded in regulations across the US, EU, Japan, and beyond. A practical tracker of what is required, by whom, and by when.
What an SBOM Scanner Does and How to Choose One
An SBOM scanner reads a software bill of materials and matches every listed component against vulnerability data. Here is how that differs from source scanning and what makes one worth trusting.
Medtronic and AdaptHealth: The Third Party Was the Vulnerability
3.8 million people notified by Medtronic. PII, PHI and insurance billing credentials exfiltrated at AdaptHealth after social engineering against a third-party contractor. Neither breach needed a software vulnerability — both needed a trusted outsider with a session.
DORA Concentration Risk: ESAs' Designation of Critical ICT Third-Party Providers
DORA Article 31 lets the ESAs designate critical ICT third-party providers (CTPPs) for direct EU-level oversight. First designations land in 2025-2026 from the Register of Information.
Software Supply Chain Security for Regulated Industries
Healthcare, finance, energy, and defense face unique supply chain security requirements. Here is how regulated industries should approach SBOM compliance and vulnerability management.
The GNU Affero General Public License v3.0, Explained
The GNU Affero General Public License v3.0 extends GPLv3 copyleft to software used over a network. Here is what AGPLv3 requires and how it differs from GPLv3.
The GPLv3 License Explained: Compliance and Risk
The GPLv3 license is a strong copyleft license that carries real obligations, and treating it as just another dependency is how companies end up with compliance and legal exposure.
Best continuous compliance monitoring platforms
A practical, no-hype comparison of continuous compliance monitoring platforms for SOC 2 and audit readiness, plus where dedicated tools fall short.
Automating Open Source License Compliance: From Manual Audits to Continuous Enforcement
Manual license audits cannot keep pace with modern dependency trees. Automated license detection, policy enforcement, and compliance documentation turn a legal bottleneck into a developer workflow.
FedRAMP 20x Phase One: 13 of 26 Pilot Reviews Completed
GSA announced FedRAMP 20x on March 24, 2025. By the end of Phase One in late September, FedRAMP had received 26 submissions and completed 13 reviews.
The 2026 SBOM compliance guide: where a software bill of materials is now required
SBOM requirements have spread from a single US executive order to regulations across sectors and continents. Here's a framework-by-framework map of where you need one in 2026.
CCPA and CPRA for Developers: What the Code Actually Has to Do
California's privacy laws are usually framed as a legal problem, but honoring opt-outs, deleting data, and maintaining reasonable security are engineering problems. Here's the developer's view of CCPA and CPRA.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.