due-diligence
Safeguard articles tagged "due-diligence" — guides, analysis, and best practices for software supply chain and application security.
9 articles
How to Actually Read a Vendor's SOC 2 Report
You skim the front, see an unqualified opinion, approve the vendor. The value is in four sections most reviewers never reach, and one of them lists the controls you are required to perform for the vendor's controls to work.
Marriott and Starwood (2018): A Breach Inherited Through an Acquisition
A factual retrospective on the Marriott breach disclosed in 2018, where attackers had been present in the Starwood reservation system since 2014, two years before Marriott acquired the company.
Best open source audit tools for M&A due diligence
A practical buyer's guide to open source audit tools for M&A due diligence, comparing ScanCode, FOSSology, ORT, Syft/Grype, FOSSA, and Black Duck.
What open source scans miss in M&A due diligence
Open source composition scans like Black Duck catch known packages and licenses — but M&A due diligence needs to catch what those scans miss too.
Communicating security posture to customers/investors via...
How to turn SBOMs into a real vendor-risk communication tool for customers and investors, and where Mend.io's scan-first approach falls short.
Open source license risk in M&A due diligence
Open source license conflicts hide in most acquisition targets' codebases. Here's why manifest-based SCA tools like Mend.io miss them in M&A diligence — and what a real audit needs.
Reachability Analysis For EU CRA Due Diligence
EU CRA enforcement asks vendors and operators to demonstrate due diligence on software components. Reachability is the evidence that makes the demonstration honest.
SBOM-Driven Due Diligence for M&A
How SBOMs have become a standard input to technical due diligence for software acquisitions, what acquirers actually look for, and how sellers should prepare.
Enterprise AI Procurement Due Diligence Checklist
AI-for-security procurement covers more than feature comparison. The due diligence checklist that surfaces structural differences between vendors.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.