Compliance
In-depth guides and analysis on compliance from the Safeguard engineering team.
304 articles
ISO 27001/27002 mapping for application security controls
ISO 27001:2022 maps 10+ Annex A controls directly to secure development. Here's how to evidence them, and where SAST-only tools like Veracode fall short.
NIST SP 800-53 control mapping for AppSec
How NIST SP 800-53's SA, RA, and SR control families map to modern AppSec — and where legacy scanners like Veracode leave supply-chain evidence gaps.
SOC 2 Type II reporting for AppSec vendors and buyers
A SOC 2 Type II badge isn't enough due diligence for AppSec vendors. Here's what to actually check in the report—scope, exceptions, and subservice carve-outs—before you trust one.
Why a Customer Trust Center matters for vendor risk reviews
Vendor security reviews stall without a live trust center. See what appsec teams check, how Veracode approaches transparency, and how Safeguard's trust center speeds reviews.
SBOM Examples: What a Real Software Bill of Materials Looks Like
Concrete SBOM examples in both SPDX and CycloneDX, showing what fields actually go in a software bill of materials and how the two formats differ in practice.
MIT License Adalah: What It Means and Its Security Implications
MIT License adalah salah satu lisensi open source paling permisif — it lets anyone use, modify, and sell the code as long as they keep the copyright notice. Here is what that permissiveness means for security and compliance.
What open source scans miss in M&A due diligence
Open source composition scans like Black Duck catch known packages and licenses — but M&A due diligence needs to catch what those scans miss too.
Software Licensing Models Explained (and Their Hidden Security Risks)
Software licensing models decide more than what you pay. Permissive, copyleft, dual, and proprietary licenses each carry compliance and security implications your SBOM needs to track.
Open source license compliance and risk management
How to manage open source license risk beyond point-in-time scans: copyleft traps, MongoDB/Elastic relicensing, and why continuous checks beat Black Duck-style audits.
How Snyk's open-source license compliance engine classifi...
How Snyk's license compliance engine groups open-source licenses and maps them to low, medium, high, and critical severity levels.
What is an Open Source Audit?
What is an open source audit, how does it compare to Black Duck's point-in-time scans, and why continuous monitoring closes the gap audits leave open.
What are Open Source Licenses?
Open source licenses govern how 96% of modern codebases can legally be used. Here's how license compliance works, where Black Duck's approach falls short, and how to close the gaps.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.