Safeguard
Tag

appsec

Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.

596 articles

Security

Interactive Application Security Testing Tools: How IAST Works and When to Use It

IAST watches your running application from the inside during normal testing, catching real, reachable flaws that static scanners can only guess at.

Jun 26, 20267 min read
AppSec

URL Scanner: How It Works and What to Use

A URL scanner checks a web address for danger before you visit or ship it — but 'URL scanner' covers two very different tools. Here is how each works and which one solves your problem.

Jun 25, 20266 min read
Security

CWE Meaning: What Common Weakness Enumeration Is and Why It Matters

The CWE meaning is simpler than it looks: a shared catalog of software weakness types. Here is how it differs from CVE and how to actually use it.

Jun 25, 20266 min read
Compliance

PCI DSS compliance for application security teams

PCI DSS 4.0's software inventory rules are enforced since March 2025. Here's why scanner-only tools like Checkmarx miss Requirements 6.3.2, 6.4.3, and 11.6.1.

Jun 25, 20267 min read
AppSec

Security in PHP: Framework-Level Protections and Common Gaps

Security in PHP improved enormously once frameworks took over escaping, CSRF, and query building. The remaining incidents live in the gaps where developers step outside those rails.

Jun 25, 20266 min read
AppSec

Code Scanning Tools: How to Choose and Use One That Works

A code scanning tool automatically inspects your source and dependencies for vulnerabilities. Here is how the main types differ and how to wire one into CI without drowning in noise.

Jun 25, 20266 min read
Security

Checkmarx API Security: What It Does and How to Use It

Checkmarx API Security discovers your real API footprint — including shadow and zombie endpoints — and correlates static and dynamic findings. Here's how it fits an AppSec program.

Jun 24, 20266 min read
Security

App Security Tools: A Practical Guide to Building Your AppSec Stack

The right app security tools do not overlap by accident — each one covers a layer the others cannot see, and the gaps between them are where breaches start.

Jun 24, 20266 min read
AI Security

Securing AI coding assistants (Claude Code, Copilot, etc.)

AI coding assistants like Claude Code and Copilot introduce new supply chain risks. Here's what's actually going wrong and how to secure your pipeline.

Jun 24, 20267 min read
Security

Enterprise Security Products: How to Build a Stack That Fits

Enterprise security products span identity, endpoint, network, cloud, and application layers. Here is how the categories fit together and how to avoid buying overlap.

Jun 23, 20266 min read
AppSec

SAST, DAST, and SCA: The Three Scanner Types You Actually Need

Each scanner type answers a different question about your application. Here's what SAST, DAST, and SCA each catch, and why running just one leaves gaps.

Jun 23, 20265 min read
AppSec

Web Application Vulnerability Scanners, Compared

Web application vulnerability scanners range from free online URL checkers to full DAST platforms — here's how the categories differ and which one actually matches your risk.

Jun 22, 20265 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

appsec (Page 14) — Safeguard Blog