appsec
Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.
596 articles
What Is Threat Modeling?
Threat modeling is the structured practice of asking what can go wrong with a system before you build it, then designing controls to match. Here's the four-question framework, how to run a session, and where it fits supply chain security.
How GitHub used secret scanning to reach 'inbox zero' on ...
GitHub spent nine months clearing 20,000+ secret scanning alerts across 15,000 repos, finding 90% were noise. Here's how they beat alert fatigue, and how Safeguard automates it.
Mobile Application Penetration Testing: A Practical Guide
How mobile application penetration testing actually works — the methodology, the tools, and what to expect from a good engagement — from someone who runs them.
XSS Payloads on GitHub: What Those Repos Contain and How to Defend
Searching for XSS payloads on GitHub turns up huge lists of test strings. Here is what they are actually for, how defenders use them responsibly, and how to stop cross-site scripting in your own code.
DAST Tools List: The Dynamic Application Security Scanners That Matter
A practical DAST tools list for 2025: the open source and commercial scanners worth knowing, what each is good at, and how to fit DAST into your pipeline.
An XSS Example That Explains How Cross-Site Scripting Works
A clear XSS example shows how unescaped user input becomes executable script in a victim's browser, and why output encoding and CSP are the fixes that hold.
DAST Automated Testing: How It Works and Why It Belongs in CI
A DAST automated test probes your running application for vulnerabilities the way an attacker would, on every build. Here is how it works and the benefits of wiring it into CI.
Unified AppSec platform vs. stitched-together point solut...
Checkmarx built its AppSec suite through years of acquisitions. Safeguard built one risk graph. Here's how to verify which model actually reduces triage work.
Checkmarx vs Veracode: platform comparison
Checkmarx and Veracode both scan code for vulnerabilities. Here is how the platforms compare, and where software supply chain security fits in.
Checkmarx alternatives for enterprise AppSec teams
Checkmarx bundles SAST, SCA, and DAST into one platform. For teams whose real gap is supply chain risk, here's how Safeguard compares on reachability, SBOM, and deployment.
SQL Injection Detected: What the Alert Means and How to Respond
A SQL injection detected alert means a scanner or WAF found input reaching your database as executable code. Here is how to confirm it, triage it, and fix the root cause.
Threat Model Examples: Walkthroughs You Can Actually Copy
Concrete threat model examples for a web app, an API, and a CI/CD pipeline, using STRIDE and data flow diagrams to show how the process works end to end.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.