Safeguard
Tag

threat-modeling

Safeguard articles tagged "threat-modeling" — guides, analysis, and best practices for software supply chain and application security.

44 articles

Vulnerability Management

MITRE ATT&CK Framework

MITRE ATT&CK maps 200+ attacker techniques, but runtime tools like Aqua only catch supply chain compromise after deployment. Here's the build-time gap and how to close it.

Apr 13, 20267 min read
AI Security

Why LLMs Are Structurally Insecure (and What That Means for Your Pipeline)

Language models are not insecure because of a bug you can patch. They are insecure by construction — non-deterministic, context-poisonable, and unreproducible. Here is how to reason about them without pretending otherwise.

Apr 12, 20267 min read
Application Security

What is Threat Modeling

Threat modeling finds the design flaws scanners can't see. Learn what it is, when to do it, and how Safeguard ties it to reachability analysis.

Apr 12, 20266 min read
Security

How to Run a Software Security Assessment

A software security assessment is a structured evaluation of an application's security posture across code, dependencies, configuration, and process. Here is how to run one that produces action, not a PDF.

Apr 12, 20266 min read
Security

"The Code Is Correct!" and Other Myths That Hide Security Bugs

Passing tests and a clean review tell you the code is correct, but correctness and security are not the same thing. Here is where the gap lives.

Apr 9, 20266 min read
AI Security

Secure Code Training for Developers: What Actually Changes Behavior

Secure code training for developers works when it is contextual, hands-on, and tied to the code they ship this week, not an annual slideshow. Here is how to build a program that sticks.

Apr 9, 20265 min read
Security

Application Security Meaning Explained

The application security meaning boils down to protecting software from threats across its whole life: design, code, dependencies, and runtime. Here is what the term actually covers.

Apr 8, 20265 min read
Security

DevSecOps Threat Modeling: Baking Threat Analysis Into Your Pipeline

DevSecOps threat modeling moves risk analysis out of one-off workshops and into the delivery pipeline, so teams find design flaws before they ship.

Apr 6, 20266 min read
Security

What Is a Security Development Model and How Do You Run One?

A security development model bakes threat modeling, code review, and testing into every stage of the SDLC instead of bolting security on at the end. Here is how the model works in practice.

Apr 2, 20266 min read
Security

Software Development Life Cycle Security: Building Security Into Every SDLC Phase

Software development life cycle security means every phase carries a security activity, not a scan bolted on at the end. Here is what belongs in each stage of the SDLC.

Mar 28, 20267 min read
Security

What Is a Product Security Assessment? A Practical Guide

A product security assessment is a structured evaluation of a product's design, code, dependencies, and deployment for exploitable weakness. Here is how to run one that finds real risk.

Mar 27, 20266 min read
AI Security

MCP Server Sandbox Escapes: Threat Model

A threat model for sandbox escapes in Model Context Protocol servers, mapping attack surfaces from tool execution environments to host processes and shared state.

Mar 25, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

threat-modeling (Page 3) — Safeguard Blog