Apps & Web

Application Security Testing APPSEC

Tools that find security flaws while software is being built: source code analysis (SAST), dynamic scanning that tests the running application (DAST), open source component and library risks (SCA), and secret scanning.

When you need it

  • You develop your own software (web, mobile, API)
  • You ship fast and cannot run a penetration test for every release
  • PCI DSS or BDDK (Turkish banking regulator) requires proof of secure software development

When you do not need it

  • Not needed if you don't develop software.
  • If an outside firm builds your software, don't buy the product yourself; require SAST/SCA reports and a pre-release penetration test in the contract.

In the development pipeline (CI/CD): SAST and SCA on code commit, DAST in the test environment. Critical findings should block the release.