Safeguard
Tag

saas-security

Safeguard articles tagged "saas-security" — guides, analysis, and best practices for software supply chain and application security.

18 articles

Application Security

Domain Verification Is the Root of Trust for Your Enterprise Tier

Claiming a domain routes new signups, enforces sign-on and can absorb existing accounts. Every control that follows inherits whatever confidence that one check produced.

Sep 18, 20265 min read
Cloud Security

Your Free Tier Is Compute You Hand to Strangers

That is the point of it, and it is also a standing offer to everyone who wants compute, a clean network position or storage for a purpose you did not intend. The abuse is rarely sophisticated.

Sep 18, 20265 min read
Application Security

Every Connected App Holds a Credential Nobody Reviews

A user clicks approve in about four seconds and an application you did not write holds a token to their data, refreshing itself indefinitely. In most products nobody can list them afterwards.

Sep 18, 20266 min read
Application Security

Anyone With the Link Is Not an Access Control

It is the absence of one, with a long identifier standing in for a decision about who should see the thing. Products ship it because customers need it, and then nobody can list what has been shared.

Sep 18, 20266 min read
Application Security

The Invitation Flow Is an Access Grant Wearing a Growth Feature's Interface

Someone mistypes a colleague's address and a stranger is in that company's tenant, because the invitation worked exactly as designed. It is built early, for frictionlessness, by whoever shipped the collaboration feature.

Sep 18, 20266 min read
Industry Analysis

Third-party risk assessment for insurtech SaaS platforms

A practical playbook for running an insurtech third-party risk assessment across vendors, APIs, and integrations before they touch policyholder data.

Aug 10, 20268 min read
Security

Device Code Phishing Rose 15x. Checking the URL Does Not Help.

Device code phishing sends victims to a genuine Microsoft page to enter a genuine code. There is no fake domain and no credential to steal. Training built on spotting bad URLs has nothing to use.

Aug 9, 20266 min read
Software Supply Chain Security

Vendor breach exposure: third-party risk lessons from the Klue incident

A single forgotten credential at Klue exposed Salesforce CRM data at 14+ companies, including Snyk and Huntress—here's what it teaches about vendor risk.

Jun 28, 20268 min read
Threat Intelligence

The Klue Breach: One Legacy Credential Turned Into a SaaS Supply Chain Attack on Salesforce and Gong

Attackers used a disused legacy credential at marketing-intelligence vendor Klue to push code that harvested customer OAuth tokens, then walked into Salesforce and Gong instances. A textbook SaaS-to-SaaS supply chain pivot.

Jun 17, 20266 min read
Compliance

SOC 2 Type II reporting for AppSec vendors and buyers

A SOC 2 Type II badge isn't enough due diligence for AppSec vendors. Here's what to actually check in the report—scope, exceptions, and subservice carve-outs—before you trust one.

Jun 17, 20268 min read
Threat Intelligence

OAuth Token Theft: The SaaS-to-SaaS Supply Chain Is the New Soft Target

The Klue and Salesloft Drift breaches showed the same pattern: steal one integration's OAuth tokens, inherit trusted access into hundreds of customer SaaS instances. Here is why third-party app grants are the supply chain risk most teams still aren't governing.

Jun 8, 20267 min read
Product

Cloud Scanning vs Hybrid Scanning: Deployment Models for ...

SaaS vs self-hosted SCA deployment compared on data residency, air-gap support, and audit scope, with a look at how Safeguard's flexible deployment model differs from cloud-only platforms.

May 20, 20268 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.