Case Studies Archives | Apiiro | Deep Application Security Posture Management (ASPM) https://apiiro.com/resources/case-studies/ Secure your development and delivery to the cloud. Wed, 07 Jan 2026 11:17:40 +0000 en-US hourly 1 https://apiiro.com/wp-content/uploads/2024/04/Favicon-2-150x150.png Case Studies Archives | Apiiro | Deep Application Security Posture Management (ASPM) https://apiiro.com/resources/case-studies/ 32 32 The Impact of AI SAST: Paddle + Apiiro https://apiiro.com/resource/the-impact-of-ai-sast-paddle-apiiro/ Fri, 26 Dec 2025 15:09:18 +0000 https://apiiro.com/?post_type=resource&p=12712 The Impact of AI SAST: Paddle + Apiiro We sat down with Jed, Senior Application Security Engineer at Paddle, to talk about the biggest challenge security teams face day to day: cutting through the noise. Jed shared how high false-positive rates and low-context findings can slow teams down, making it harder for developers to confidently […]

The post The Impact of AI SAST: Paddle + Apiiro appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>

The Impact of AI SAST: Paddle + Apiiro

We sat down with Jed, Senior Application Security Engineer at Paddle, to talk about the biggest challenge security teams face day to day: cutting through the noise. Jed shared how high false-positive rates and low-context findings can slow teams down, making it harder for developers to confidently prioritize the issues that truly matter.

Here are the highlights:

Q: What was broken with legacy AppSec tools?

A: From my experience — and what I’ve seen other Application Security Engineering colleagues deal with — it creates a lot of noise.

I think that’s really the core issue.

With such a high rate of false positives, and findings that often lack context, it makes it difficult for me and other developers to confidently say, “Okay — which of these issues actually matter and should be prioritized?”

When you’re staring at a sea of massive amounts of results, it’s hard to identify what’s truly important.

I really think the high false positive rate is the main issue for a lot of other Application Security Engineers, too.

Q: How does the high rate of false positives impact developers?

A: Sometimes we try to filter things down and only pass off results that we think should be looked at.

But we’ve seen in the past that when we try to get developers to own their areas of development, it’s hard to even get started if there are massive amounts of results.

If you see thousands of false positives, it’s like… where do I even begin?

It often turns into paralysis by analysis.

You try to contribute and be productive, but you eventually just give up because it’s not useful in the end.

Q: What impact did Apiiro have?

A: Apiiro massively reduced the false positives.

In our environment, we’ve seen something like a 90%+ reduction in findings.

And when I say “findings,” I mean the bad kind — the ones that weren’t useful — so we were able to cut that off entirely.

It also made things better because the new AI capabilities from APO with SaaS help give more context into why a finding matters.

It helps you understand how to address it, and what the actual core issue is.

So it dramatically reduced the false positive rate — which was the main issue — and it helps surface the issues that truly matter.

It makes our lives easier.

Work becomes faster, easier, and more productive in that area.

The post The Impact of AI SAST: Paddle + Apiiro appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>
Digital Infrastructure Leader Scales Small Development Team with Apiiro https://apiiro.com/resource/digital-infrastructure-leader-scales-small-development-team-with-apiiro/ Fri, 20 Dec 2024 12:59:18 +0000 https://apiiro.com/?post_type=resource&p=9883 Code-to-Runtime + Deep Code Analysis = More fixes, fewer alerts KPI We sat down with Director of Application Security Daniel Krasnokucki, who built from scratch a team dedicated to securing application architecture for a development community 1500 strong at a leading digital infrastructure provider. Here are the highlights: Q: What do you expect from a […]

The post Digital Infrastructure Leader Scales Small Development Team with Apiiro appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>

Code-to-Runtime + Deep Code Analysis = More fixes, fewer alerts

KPI

  • 1500+ Developers
  • 35 AppSec Experts
  • 1 Unified Dashboard – More Alerts Fixed than Alerts Detected in 2024

We sat down with Director of Application Security Daniel Krasnokucki, who built from scratch a team dedicated to securing application architecture for a development community 1500 strong at a leading digital infrastructure provider.

Here are the highlights:

Q: What do you expect from a top-performing ASPM?

A: Daniel and his team needed an application security posture management solution that could…

  • Monitor not only scanning tools, but workflow management and ticketing systems to detect and analyze what developers were planning.
  • Be predictive. Prioritize not only what is in code today, but what will be in code tomorrow (or 6 months from now).
  • Provide full dashboard customization options, including advanced filtering and timelines.

Q: What impact has your ASPM had on your team?

A: A small team with big results.

  • For the past year, the team has met their goal to fix more vulnerabilities than they have detected.
  • The ability to tie code to tickets in Jira allows the team to view commits and code evolution in a single, unified timeline via the Apiiro dashboard.
  • More confident answers to security review questionnaires, and more advanced threat modeling based on the Apiiro feedback loop.

Q: How does code-to-runtime align with your needs?

A: One unified timeline for tracking the origin of vulnerabilities.

  • An automated solution for mapping, tagging, and labeling vulnerabilities
  • Developers can focus on what matters most – fixing the most critical risks in a timely manner, and getting back to feature work.

Q: How does code-to-runtime reduce your team’s MTTR?

A: “Because developers know what to mix, it’s much easier to see results in minutes or hours rather than days or weeks.”

  • Less dwell time, better results – a remediation graph that shows a decrease in the amount of time between detection and remediation in product.

See how Apiiro can meet the high standard of excellence for your AppSec engineers – book a demo today.

The post Digital Infrastructure Leader Scales Small Development Team with Apiiro appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>
Case Study: How LTP and Apiiro Together Forge a Stronger, Resilient Framework https://apiiro.com/resource/apiiro-case-study-how-ltp-and-apiiro-together-forge-a-stronger-resilient-framework/ Tue, 12 Nov 2024 19:52:55 +0000 https://apiiro.com/?post_type=resource&p=9663 How Apiiro helped LTP develop capabilities to build an SLA/MTTR framework for code security, prioritize vulnerabilities via filtering in software composition analysis (SCA), and reduce their reliance on multiple security tools, resulting in significant time savings and improved DevSecOps processes.

The post Case Study: How LTP and Apiiro Together Forge a Stronger, Resilient Framework appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>

How LTP and Apiiro Together Forge a Stronger, Resilient Framework

Background

Digital asset prime brokers like LTP depend on a complex suite of interconnected applications to better serve their clients and further innovation in the digital asset marketplace. As their security team sought to place greater emphasis on identifying and managing vulnerabilities across these applications, they turned to Apiiro. Our team offered a solution to help streamline their security processes, reduce vulnerability management times, and enhance their overall application security posture.

Highlights

Challenge

LTP’s diverse and complex business operations require robust support from external experts to assist in identifying, managing, and addressing vulnerabilities, including common weakness enumerations (CWE) and CVEs in application code. This collaboration with external teams is crucial to ensure the comprehensive validation of application vulnerabilities, such as those identified by Apiiro, and to maintain smooth and secure operations across our extensive systems.

Solution

Apiiro, with the support of Aerowave Technologies, provided LTP with a unified AppSec platform, offering full support of supply chain levels for software artifacts (SLSA – which includes SAST, SCA, and pipeline security) and a high-level, consolidated view of their application security.

Result

LTP developed capabilities to build an SLA/MTTR framework for code security, prioritize vulnerabilities via filtering in software composition analysis (SCA), and reduce their reliance on multiple security tools, resulting in significant time savings and improved DevSecOps processes.

The Challenge: Managing Vulnerabilities with Complex Business Operations Duties

The complexity and breadth of LTP’s operations demand a multi-faceted approach to reducing vulnerability exposure. Success is measured by two key performance indicators: external vulnerability discovery post-launch and internal discovery pre-launch. These metrics, evaluated by the number and severity of vulnerabilities, present a challenge given the scale and complexity of LTP’s operations.

Each day, LTP’s security team reviews the previous night’s security events, analyzes them, and optimizes alarm rules. They also conduct baseline scans and assess business risks to ensure smooth operations. Given the complexity and scale of their applications, the team continuously seeks to enhance their capabilities by leveraging external expertise and support, further reinforcing their robust security framework.

Given the scale and demands of their business, LTP sought external tools and expert teams to assist in identifying and managing vulnerabilities, particularly those with business-critical risks. These tools needed to streamline security processes, consolidate key features like SAST, SCA, and secret detection, and ensure seamless integration with ticketing systems like JIRA.

The Solution: A Unified Platform with Comprehensive Security Capabilities

LTP chose Apiiro after a successful proof of concept (POC), recognizing its comprehensive support for single supply chain levels for software artifacts (SLSA), including SAST, SCA, and pipeline security. Apiiro’s ability to provide a well-rounded view of application security complemented LTP’s already robust security practices, further strengthening their overall security posture.

With the assistance of Aerowave, Apiiro helped LTP consolidate their security tools into a single platform. This consolidation provided LTP with multiple filters in their SCA processes, allowing them to prioritize vulnerabilities based on factors like whether they were used in code or exploitable. Additionally, Apiiro’s integration capabilities with Github, JIRA, and future CNAPP solutions were crucial in streamlining LTP’s security processes.

Result: Streamlined Processes and Improved DevSecOps

Apiiro’s solution empowered LTP to build an SLA/MTTR framework for their code security, which in turn helped them demonstrate the value of their security team. The ability to easily view security checks based on each repository allowed LTP to prioritize their work efficiently.

By streamlining vulnerability management and enhancing their DevSecOps processes, LTP was able to optimize their security efforts, allowing the team to allocate resources more efficiently while maintaining their strong focus on security. Apiiro’s unified platform eliminated the need for multiple tools, saving LTP considerable time and effort in learning and integrating different systems.

Moreover, Apiiro’s continuous code monitoring enabled LTP’s developers to not only see and detect risks in their components, but also to download a fixed version, which greatly accelerates the process of reducing security risk.

In the future, Apiiro’s strong integration capabilities will enable the LTP team to integrate AppSec workflows with their Aqua CNAPP, deepening the holistic view of security across multiple layers.

Conclusion

Security is a core principle and a non-negotiable priority for LTP. They consistently dedicate substantial resources and effort to building and maintaining a robust security framework, ensuring that every aspect of their operations is safeguarded. LTP’s proactive investment in advanced technologies and expert teams reflects their commitment to not just meeting but exceeding industry standards. By partnering with Apiiro, LTP further enhances their capabilities, leveraging Apiiro’s solutions to streamline processes, reduce MTTR, and lower vulnerability discovery scores. This collaboration, built on LTP’s foundational focus on security, has strengthened their overall security posture, enabling them to effectively manage risks, ensure business continuity, and achieve growth.

LTP is a premier prime brokerage serving sophisticated investors in the digital asset space, with security as the cornerstone of their operations. Recognizing the complexity and scale of their business, LTP prioritizes security above all else, ensuring that their infrastructure is fortified against any potential risks. In pursuit of maintaining these high standards, LTP chose to collaborate with us at Apiiro. Our comprehensive security solutions are tailored to meet LTP’s rigorous demands, enabling us to support their mission of ensuring uninterrupted business continuity and maintaining a robust security posture across all aspects of their operation.


The post Case Study: How LTP and Apiiro Together Forge a Stronger, Resilient Framework appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>
Case Study: How Cloudera balances development speed and product security with Apiiro https://apiiro.com/resource/cloudera-case-study-development-speed-product-security-aspm/ Mon, 08 Apr 2024 16:16:21 +0000 https://apiiro.com/?post_type=resource&p=7716 Learn how Apiiro helped Cloudera consolidate their AppSec tools and get risk-based context to reduce their backlogs and meet customer security and regulatory requirements.

The post Case Study: How Cloudera balances development speed and product security with Apiiro appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>

How Cloudera balances development speed and product security with Apiiro

Background

For an organization such as Cloudera that manages huge amounts of data across truly hybrid cloud and on-premise environments and supports many high-profile, highly-regulated enterprise customers, security has to be more than just a feature. It’s core to their business.

Highlights

  • Cloudera needed a partner to assist in speeding up the time-to-resolution of security vulnerabilities, as well as help them assess their security posture and gaps.
  • Apiiro provided Cloudera with a continuous inventory of their application components, including open-source dependencies, licenses, and all APIs.
  • Cloudera used Apiiro to consolidate security tools and got the automated context they needed to surface business-critical risks proactively and fix them faster.
Screenshot

The challenge: Meeting security expectations for a complex application

Cloudera knows that maintaining a strong AppSec program and implementing top-notch tools is of utmost importance. Their product security team is also subject to strict SLAs for addressing critical security and compliance risks to fulfill their customers’ and partners’ requirements.

Because their applications are so multifaceted and quickly evolving to drive customer value, making sense of their application and software supply chain threat landscape had always been a challenge. And with several sources of security data being managed and addressed independently, Cloudera needed a way to consolidate and optimize their workflows to fix critical issues faster and proactively.

The solution: Holistic application visibility and risk-based automation

Cloudera deployed Apiiro and gained a full inventory of their applications—including open source packages, data flows, APIs, and much more. As part of Apiiro’s inventory, Cloudera also got insight into their connections with one another, their associated risks, and their historical changes. Apiiro’s deep code analysis provided the foundation for the application security team to differentiate vulnerabilities from risks. 

Cloudera knew that the key for security to keep up with agile development was to ensure that the product was built securely from the beginning. Apiiro helped the Cloudera product security team take that goal a step further by “shifting security everywhere,” ensuring that security checks are accomplished throughout the lifecycle without slowing developers down.

The impact: Reducing backlogs with deep code-to-cloud context

With Apiiro’s holistic approach to application and software supply chain security, Cloudera’s product security team was empowered to consolidate their AppSec tools and streamline their entire program.

  • Apiiro gave Cloudera a thorough view of their applications before and after deployment, from the code to the cloud, to deeply understand their security posture and assess their security coverage gaps.
  • By consolidating their independent tools and providing invaluable business and application context, Apiiro helped Cloudera surface the most critical risks to cut through the noise, reduce their backlog, and save time fixing risks.
  • With Apiiro’s continuous code monitoring and automated developer guardrails on new pull requests, Cloudera was able to empower developers to see the issues before they are released—without security getting involved and with no need for additional training.

Cloudera is the preferred enterprise data management and analytics platform for the world’s top companies in almost every industry. With its open data lakehouse, Cloudera empowers people to transform data anywhere into trusted enterprise AI.

Industry: B2B Software, Cloud computing
Employees: 3000+
Developers: 2000+

Get the case study PDF

“We are able to empower the developers to see the issues before they occur and before they make it into the product and they require very little or no training to do that.”

—Natalia Belaya, Chief Information Security Officer (CISO), Cloudera

The post Case Study: How Cloudera balances development speed and product security with Apiiro appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>
Case Study: How Paddle created a force multiplier for AppSec with Apiiro https://apiiro.com/resource/paddle-case-study/ Tue, 26 Mar 2024 12:15:12 +0000 https://apiiro.com/?post_type=resource&p=7434 Learn how Apiiro’s ASPM platform enabled Paddle to adopt a developer-centric and risk-based approach to AppSec and act as a force multiplier for their team.

The post Case Study: How Paddle created a force multiplier for AppSec with Apiiro appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>

How Paddle created a force multiplier for AppSec with Apiiro

Highlights

  • As Paddle built out its application security program, they sought a partner to enable them to act as a force multiplier to boost their proactive security efforts and focus on the most business-critical risks.
  • With Apiiro’s deep ASPM platform, Paddle was able to get an aggregated view of their application inventory and a single hub for enforcing security policies earlier in the development lifecycle.
  • Apiiro not only ingested and enriched Paddle’s existing security testing but also consolidated and expanded their security coverage with next-gen open source security, secrets security, and software supply chain security.
Screenshot 2024-03-23 at 1.07.34 PM

The challenge: Delayed releases due to reactive security

As a payments infrastructure provider, Paddle’s application threat landscape is significant—including all the risks associated with payment security and privacy, as well as the security of the Paddle application itself. As a small application security team building out its AppSec program, Paddle knew they needed a way to multiply their efforts and foster better collaboration with development teams.

Vulnerabilities from their existing tools were being surfaced too late in the SDLC, leading to delayed code releases and internal friction. But collaborating with the developers or engineering teams to address risks was also challenging because they didn’t have insight into who owned what.

Paddle sought a solution to help them adopt a proactive, developer-centric approach to application security and optimize their existing tooling and manual risk assessment processes such as pen tests, security code reviews, and threat modeling.

The solution: Developer-centric and risk-based AppSec

Paddle rolled out Apiiro in a staged approach to gain visibility across its application estate, use that context to build risk-based policies and developer workflows, and then measure and optimize their program success over time.

Through Apiiro’s easy-to-install GitHub integration, Paddle quickly got a complete inventory across their nearly 500 repositories, including technologies, open source usage, exposed secrets, sensitive data, and development behavior. That visibility, coupled with the ingestion of vulnerability findings from existing tools, gave them an aggregated view of risks. It also enabled them to prioritize based on business impact and risk likelihood and connect risks to their root cause in code and developer owner. 

Apiiro also provides a single hub for implementing policy-as-code, helping automate developer guardrails and enforce application security best practices on every pull request. This allows Paddle’s application security team to meet the developers where they’re comfortable with a common taxonomy.

The impact: Force multiplying application security

Apiiro’s continuous application inventory, policy-as-code engine, and application risk control plane have acted as a force multiplier for the Paddle application security team.

  • Apiiro monitors 100+ pull requests per week, blocking high-risk changes that need additional assessments, and giving developers the remediation context they need right then and there.
  • By saving them time combing through all code changes to identify only relevant, risky ones, Apiiro acts as a force multiplier for the Paddle application security team, giving them back 2 days’ worth of work per week.
  • Apiiro’s reports and dashboards allow everyone—from executives to security champions—to measure risk and understand security’s impact on engineering productivity metrics such as those outlined in DORA.

Bonus use case: Deepening security coverage with Apiiro SCA + SSCS

In addition to leveraging Apiiro’s ASPM to solve their core challenge of enabling a developer-centric approach to security, Paddle saw Apiiro as an opportunity to consolidate and deepen their application security testing coverage.

Paddle now leverages Apiiro’s open source and software supply chain security solutions, giving them fully integrated visibility and risk detection across packages, repositories, and pipelines.

“Since introducing Apiiro’s Software Supply Chain Security (SSCS) at Paddle, we have been able to ensure pipelines are set up securely and have improved insights into the configuration of our source control repositories—a capability not provided by traditional AppSec tools. This heightened visibility, coupled with Apiiro’s risk-based prioritisation and policy engine, instills confidence in our capability to continually measure supply chain risk and assess against best practice moving forward.

– Colin Barr, Senior Engineering Manager – Application Security, Paddle

Paddle is a payments infrastructure provider, enabling software companies to respond faster and more precisely to every growth opportunity.

Industry: B2B Software
Employees: 300+
Developers: 80+

Get the case study PDF

“The unique value that Apiiro provides Paddle is as a force multiplier we can do more with less, we can meet the developers where they’re comfortable, we can provide them the information that they need to fix or to mitigate issues in a single unified view.”

—Jonny Herd, VP of Information Security & Enterprise Technology, Paddle

The post Case Study: How Paddle created a force multiplier for AppSec with Apiiro appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>
Case Study: How SoFi empowers development velocity while reducing application risk https://apiiro.com/resource/sofi-case-study/ Wed, 28 Feb 2024 20:42:57 +0000 https://apiiro.com/?post_type=resource&p=7184 Learn how Apiiro's deep code analysis and automation enable SoFi to prevent new risks without blocking developers.

The post Case Study: How SoFi empowers development velocity while reducing application risk appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>

How SoFi empowers development velocity while reducing application risk

Highlights

  • As SoFi started building out its application security program, they sought a partner to go beyond ad hoc AppSec testing, lack of application visibility, and hours spent on security design reviews.
  • With Apiiro’s help, SoFi’s application security team reduced time spent identifying, assessing, and addressing new application risks from days to hours. 
  • In supporting their mission to enable versus block developers, Apiiro gave SoFi the context and automation they needed to define and trigger risk-based policies at the right time in the right place.
Apiiro and SoFi in conversation

The challenge: Supporting business velocity while reducing application risk

Like most fintech organizations that depend on agile development processes to be constantly innovating, SoFi meticulously balances its organizational goals with its risk appetite and compliance requirements. For the SoFi application security team, that means deeply understanding and mitigating application risk without slowing down development velocity. 

As a team of 16 supporting 2000+ developers across 5200+ repositories, the SoFi AppSec team knew they couldn’t possibly manually review each and every code change. They sought a partner to help them gain visibility across their application portfolio to focus on the most business-critical risks, scale their security review efforts, and optimize the time they spent fixing risks.

The solution: Visibility-first context and AppSec automation

With Apiiro’s application security posture management (ASPM) platform, SoFi’s AppSec team was able to build an exhaustive inventory of their application technologies, components, and attack surface—from repositories, APIs, and open source packages to contributor activity, material code changes, and beyond. Apiiro also provides out-of-the-box insight into exposed secrets and sensitive data in code, open source vulnerabilities, API security weaknesses, and more, giving them a single pane of glass for prioritizing application security findings.

Apiiro gives SoFi’s team continuous oversight into potential risks that need security design reviews by analyzing commits for material code changes in the context of their application. Leveraging Apiiro’s policy engine, SoFi can define exactly what they categorize as a critical business risk. Then, whenever a risky material code change or risk is flagged, Apiiro’s workflows trigger the appropriate process, such as creating a security design review ticket.

The impact: Minimizing and optimizing security reviews

Combining automation and context powered by Apiiro’s deep code analysis enables SoFi to prevent new risks without blocking developers.

  • By triggering the right processes at the right time with the right context, SoFi’s AppSec team went from spending hours analyzing design reviews to 5-15 minutes.
  • By tying critical risks to their relevant code owners, Apiiro enabled SoFi to reduce their mean time to remediation (MTTR) from 8 days to 10 minutes.
  • SoFi’s AppSec team got near-instant visibility across their entire application portfolio, including subsidiaries, that they didn’t have before, allowing them to focus on areas to improve risk with minimal effort.

SoFi (NASDAQ: SOFI) is a member-centric, one-stop shop for digital financial services on a mission to help their more than 7.5 million members borrow, save, spend, invest, and protect their money better.

Industry: Financial Services
Employees: 5000+
Developers: 2000+

Get the case study PDF

“There’s a lot of ASPMs out there. I don’t think we have run across one that’s doing code analysis the way Apiiro does and providing us the insights that Apiiro does.”

—Zach Schulze, Sr. Staff Application Security Engineer, SoFi

The post Case Study: How SoFi empowers development velocity while reducing application risk appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>
GSoft Case Study https://apiiro.com/resource/gsoft-case-study/ Wed, 22 Feb 2023 15:41:18 +0000 https://apiiro.com/?post_type=resource&p=2550 GSoft Case Study GSoft lacked visibility across all repositories, making it challenging to properly classify, recognize, and focus on the most critical risks. In addition, without automation, their two-person team could not continuously monitor changes made by 130+ developers to fix issues that were most important to the business and their customers. Solution Results

The post GSoft Case Study appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>

GSoft Case Study

GSoft lacked visibility across all repositories, making it challenging to properly classify, recognize, and focus on the most critical risks. In addition, without automation, their two-person team could not continuously monitor changes made by 130+ developers to fix issues that were most important to the business and their customers.

Solution

  • Apiiro indexes all of the application components so that even their small AppSec team can quickly identify and prioritize high-risk vs. low-risk issues.
  • Compared to other application security testing tools, the Apiiro platform analyzes every pull request in seconds to significantly decrease the time to remediate.
  • Apiiro’s SCA functionality activates as soon as it is connected to the source control manager and immediately surfaces all of the open-source elements without a need for extensive and time-consuming integrations.

Results

  • Apiiro saves GSoft many hours of AppSec work daily on integrations between security tools and applications, leading to significant cost savings and improved efficiencies.
  • Apiiro also saves 30 minutes per day for every active developer, which amounts to 65 hours per day across the whole team, giving it an additional capacity of eight developers.
  • The saved development and application security time is now applied to delivering more customer value and increased time-to-market velocity for important product features.

Montreal-based software company, GSoft, leverages Apiiro to index all application components to prioritize high-impact risks and significantly decrease remediation response times.

Read the full case study

“We didn’t know we needed Apiiro until it showed us all the information that existed that we had no idea was out there and that our team was responsible for.”

–Edouard Shaar, Application Security Specialist, GSoft

The post GSoft Case Study appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>
Navan Case Study https://apiiro.com/resource/navan-case-study/ Fri, 12 Aug 2022 13:11:28 +0000 https://apiiro.com/?post_type=resource&p=2052 How Navan automated AppSec governance throughout the development lifecycle with Apiiro Highlights The challenge: Automating AppSec early and at scale Like many AppSec teams, Navan’s didn’t have nearly enough cycles or resources to manually keep up with the hundreds of pull requests created each week. Even with multiple AppSec tools in place, they couldn’t guarantee […]

The post Navan Case Study appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>

How Navan automated AppSec governance throughout the development lifecycle with Apiiro

Highlights

  • Navan gained nearly instant visibility into all its components, risks, and material changes across repositories and applications.
  • Navan replaced manual security reviews and alert triage with automated risk assessments and prioritization across hundreds of weekly pull requests.
  • Navan shifted application security earlier in the development lifecycle with actionable, risk-based developer guardrails.

The challenge: Automating AppSec early and at scale

Like many AppSec teams, Navan’s didn’t have nearly enough cycles or resources to manually keep up with the hundreds of pull requests created each week. Even with multiple AppSec tools in place, they couldn’t guarantee that new changes were risk-free. Inundated with alerts, they also struggled to understand how constant code changes would actually impact their application attack surface.

Without a consolidated and automated way to prioritize noisy alerts, the Navan AppSec team needed a solution to reduce noise, ensure accuracy, and determine the most critical risks that needed to be remediated.

The solution: Continuous visibility and governance

Shortly after integrating Apiiro into their source control manager (SCM), Navan started getting continuous visibility into risky areas and behavior. By consolidating findings from native and third-party tools into a single pane of glass, Apiiro was able to correlate, deduplicate, and prioritize alerts to focus on what matters. By knowing what was and wasn’t a real risk, the Navan AppSec team freed up triage cycles and dramatically cut down the alert backlog.

After assessing and understanding their risk, Navan implemented automated workflows to alert their AppSec team when a risky commit or pull request was introduced. That proactive approach and Apiiro’s ability to tie risks to code owners decreased the time it took them to remediate issues.

The impact: Reducing overall application risk

By automating Navan’s application security visibility, risk assessment, remediation, and prevention, Apiiro helped optimize its team resources while reducing its overall application risk.

  • Apiiro enables Navan to continuously and automatically maintain visibility across their applications and identify material changes that may create risk.
  • Apiiro’s risk-based alerts allow the AppSec team to ensure that out of hundreds of pull requests each week, risky changes are identified automatically.
  • With Apiiro’s built-in code security solutions, Navan can gain visibility into risks such as exposed API keys and credentials in code, sensitive data, and more at scale.

Navan is a corporate travel, card and expense management platform that empowers its customers to seamlessly manage business travel, corporate cards and expenses using AI-driven technologies.

Industry: Corporate Travel Management
Employees: 2K+
Developers: 250+

Read the full case study

“Apiiro recognizes and classifies risks in a way I have not seen any other company do”

–Tarik Ghbeish, Manager of Application Security at Navan

The post Navan Case Study appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>
Rakuten Rewards Case Study https://apiiro.com/resource/rakuten-rewards-case-study/ Thu, 11 Aug 2022 18:19:39 +0000 https://apiiro.com/?post_type=resource&p=2047 Rakuten Rewards Case Study Challenges Solution Results

The post Rakuten Rewards Case Study appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>

Rakuten Rewards Case Study

Challenges

  • Understanding application risk as early as product design through software development and production systems.
  • As a security and risk team, it is difficult to ensure effective security across thousands of projects and repositories. People cannot effectively understand risk posture at scale without automation.

Solution

  • Apiiro helps with collecting, organizing, and continuously tracking all data that is risk-related and can be tied to code.
  • Apiiro creates a risk-based inventory that is continuously updated so the security team can understand their application security posture at any point, in real-time.
  • Apiiro not only prioritizes the right risks, but provides a top-down view so Rakuten Rewards can understand their overall application risk and drill-down to the details, as needed.
  • Apiiro first sheds light on technology with its inventory and then uses context to help make risk-based security decisions

Results

  • Apiiro workflows save hundreds of hours every month by automating previously-manual tasks such as prioritizing alerts, investigating risks, and
    remediating vulnerabilities.
  • Apiiro enables Rakuten Rewards to leverage context to make risk-based application security decisions, improve its risk posture and Shift Left.
  • Improves efficiency by continuously correlating and orchestrating code and infrastructure security alerts in one platform.

Rakuten Rewards was founded in in 1998 as eBates and was acquired by Japanese online retailing company Rakuten in 2014. The company provides cash-back and shopping rewards. It has 12 million members who have earned over $1 billion in Cash Back at their favorite stores

Read the full case study

“With Apiiro, our security team is saving hundreds of hours every month”

-Cloud Security Architect at Rakuten Rewards

The post Rakuten Rewards Case Study appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>
Kaltura Video Case Study https://apiiro.com/resource/application-security-engineer-from-kaltura-on-apiiro/ Thu, 02 Sep 2021 03:59:19 +0000 https://apiiroproj.wpengine.com/?post_type=resource&p=644 Kaltura Video Case Study Video transcript:  I’m Roy Avrahamy, an Application Security Engineer at Kaltura. We have over 200 developers and only one me. I created a Kultura Aplication Security function from scratch, and Apiiro provides me with the visibility and context I need to build a mature and measurable AppSec program. So first, Apiiro […]

The post Kaltura Video Case Study appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>

Kaltura Video Case Study

Kaltura Video

Video transcript: 

I’m Roy Avrahamy, an Application Security Engineer at Kaltura. We have over 200 developers and only one me. I created a Kultura Aplication Security function from scratch, and Apiiro provides me with the visibility and context I need to build a mature and measurable AppSec program. So first, Apiiro helps me discover all of our assets across the organization. It gives me visibility to all of my products in the repositories and contributors. And, I’ve used Apiiro to understand and quantify our application risk and to help me prioritize the risks that can have an impact on my business.

Apiiro’s automation workflows help me to do more with my time instead of all the manual processes I used to perform. I use Apiiro’s governance rules to automate our processes with the context we need to make better and smarter decisions. One of our recent focuses has been on finding and removing secrets in code. So, every time Apiiro detects a secret, it not only automatically notifies me and the developers that committed the code, but it gives us essential context, such as whether the application is internet facing or stores sensitive information. I believe in Apiiro much more than for secrets in code. But, it’s a great example of how Apiiro is helping us build a mature and measurable Application Security and the risk for it.

The post Kaltura Video Case Study appeared first on Apiiro | Deep Application Security Posture Management (ASPM).

]]>