
Featured Insights
SOC 2 Change Management with Tickets Instead of CI/CD
TL;DR Change management maps to CC8.1, which has 14 Points of Focus covering authorization, design, testing, approval, deployment, segregation of ...
Filter by Tag
SOC 2 Secure Development with Self-Hosted GitLab
TL;DR
- The same Trust Services Criterion that governs infrastructure changes governs code changes: CC8.1, change management
- Self-hosted GitLab is the...
Consulting as Code: Running Cybersecurity on GitHub
For years, programmers had an unfair advantage over the rest of us.
Not because they could build software. Because they could access data. Rich,...
What Project Glasswing Actually Means for Your Security Program
I have been thinking about what Anthropic's Project Glasswing announcement actually means for the clients we advise. The honest answer is that it...
Automate CI/CD Security for SOC 2: SAST, SCA, DAST Integration Guide
As a CTO, securing your CI/CD pipeline is critical for SOC 2 compliance. This guide shows you how to automate essential security scans, Container...



