Safeguard
Topic

Compliance

In-depth guides and analysis on compliance from the Safeguard engineering team.

304 articles

Compliance

ISO 27001/27002 mapping for application security controls

ISO 27001:2022 maps 10+ Annex A controls directly to secure development. Here's how to evidence them, and where SAST-only tools like Veracode fall short.

Jun 17, 20267 min read
Compliance

NIST SP 800-53 control mapping for AppSec

How NIST SP 800-53's SA, RA, and SR control families map to modern AppSec — and where legacy scanners like Veracode leave supply-chain evidence gaps.

Jun 17, 20267 min read
Compliance

SOC 2 Type II reporting for AppSec vendors and buyers

A SOC 2 Type II badge isn't enough due diligence for AppSec vendors. Here's what to actually check in the report—scope, exceptions, and subservice carve-outs—before you trust one.

Jun 17, 20268 min read
Compliance

Why a Customer Trust Center matters for vendor risk reviews

Vendor security reviews stall without a live trust center. See what appsec teams check, how Veracode approaches transparency, and how Safeguard's trust center speeds reviews.

Jun 17, 20267 min read
Compliance

SBOM Examples: What a Real Software Bill of Materials Looks Like

Concrete SBOM examples in both SPDX and CycloneDX, showing what fields actually go in a software bill of materials and how the two formats differ in practice.

Jun 16, 20265 min read
Compliance

MIT License Adalah: What It Means and Its Security Implications

MIT License adalah salah satu lisensi open source paling permisif — it lets anyone use, modify, and sell the code as long as they keep the copyright notice. Here is what that permissiveness means for security and compliance.

Jun 16, 20265 min read
Compliance

What open source scans miss in M&A due diligence

Open source composition scans like Black Duck catch known packages and licenses — but M&A due diligence needs to catch what those scans miss too.

Jun 15, 20268 min read
Compliance

Software Licensing Models Explained (and Their Hidden Security Risks)

Software licensing models decide more than what you pay. Permissive, copyleft, dual, and proprietary licenses each carry compliance and security implications your SBOM needs to track.

Jun 14, 20267 min read
Compliance

Open source license compliance and risk management

How to manage open source license risk beyond point-in-time scans: copyleft traps, MongoDB/Elastic relicensing, and why continuous checks beat Black Duck-style audits.

Jun 12, 20267 min read
Compliance

How Snyk's open-source license compliance engine classifi...

How Snyk's license compliance engine groups open-source licenses and maps them to low, medium, high, and critical severity levels.

Jun 9, 20267 min read
Compliance

What is an Open Source Audit?

What is an open source audit, how does it compare to Black Duck's point-in-time scans, and why continuous monitoring closes the gap audits leave open.

Jun 9, 20267 min read
Compliance

What are Open Source Licenses?

Open source licenses govern how 96% of modern codebases can legally be used. Here's how license compliance works, where Black Duck's approach falls short, and how to close the gaps.

Jun 9, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

Compliance (Page 5) — Supply Chain Security Blog | Safeguard