Security Learning Center
Your comprehensive guide to AI coding security, ACSM, and modern application security concepts.
Your comprehensive guide to AI coding security, ACSM, and modern application security concepts.
AI coding tools can introduce security vulnerabilities just like human developers. Learn about the unique risks and how to address them.
Secure by design means building security into software from the start rather than adding it later. Learn how this principle applies to AI-assisted development.
AI coding agents are autonomous software systems that can write, modify, and debug code by understanding natural language instructions and project context.
ACSM is a security discipline focused on securing AI-assisted software development environments with real-time guardrails for AI coding agents.
Agentic coding refers to AI systems that autonomously write, modify, and manage code with minimal human intervention, operating as intelligent coding agents.
Compare Agentic Coding Security Management (ACSM) with Dynamic Application Security Testing (DAST) to understand their different roles in application security.
Understand the differences between Agentic Coding Security Management (ACSM) and Static Application Security Testing (SAST), and when to use each approach.
A comparison of AI-powered code review tools for security, including Corridor, Greptile, CodeRabbit, and Snyk.
A look at AI-native static analysis tools built for modern development workflows, including real-time security for AI coding agents.
A comparison of the top static application security testing (SAST) tools, including Corridor, Semgrep, SonarQube, and Checkmarx.
Application security focuses on finding, fixing, and preventing security vulnerabilities in software applications throughout their lifecycle.
Cross-site scripting allows attackers to inject malicious scripts into web pages viewed by other users. Learn about the different types and how to prevent them.
DevSecOps integrates security practices into the software development lifecycle, automating security testing and making it part of the development workflow.
Infrastructure scanning tools analyze configuration files for security misconfigurations in cloud resources, containers, and infrastructure-as-code templates.
Secrets detection tools scan code and commits for accidentally exposed credentials, API keys, and other sensitive data before they reach version control.
Supply chain attacks target the dependencies and build processes that software relies on. Learn about the risks and how to protect your projects.
SQL injection occurs when user input is improperly included in database queries, allowing attackers to manipulate or extract data. Learn how it works and how to prevent it.
Vulnerability management is the process of identifying, evaluating, and addressing security vulnerabilities in software and systems.
CWE is a community-developed list of software and hardware weakness types, providing a common language for describing security vulnerabilities.
DAST tests running applications by simulating attacks to find runtime vulnerabilities like authentication issues and server misconfigurations.
IAST combines aspects of static and dynamic testing, analyzing applications from within during runtime to identify vulnerabilities with higher accuracy.
Software Composition Analysis identifies vulnerabilities and license issues in open source dependencies, helping teams manage the risks of third-party code.
SAST analyzes source code to identify security vulnerabilities without executing the program, helping teams find issues early in development.
The OWASP Top 10 is a regularly updated list of the most critical web application security risks, serving as a standard awareness document for developers.
Hooks are deterministic scripts that execute at specific points in the AI coding workflow, enabling security checks and policy enforcement that run every time.
MCP is a protocol that allows AI coding agents to interact with external tools and services, enabling them to access databases, APIs, and security systems.
Best practices for writing secure code when working with AI coding agents, including review strategies, guardrails, and common pitfalls to watch for.
Security guardrails are automated controls that prevent or flag potentially dangerous actions, keeping development moving while maintaining security standards.