From the SecTests team

Technical writing on appsec, vulnerability management, compliance, and building security into your development workflow.

Jan 28, 2025 · Dana Ortiz

Introducing API Security Scanning in SecTests

We shipped first-class API security testing. Import your OpenAPI spec, point at your endpoints, and get coverage for BOLA, injection, and auth bypass.

Sep 18, 2024 · Alex Koval

The OWASP Top 10 in 2024: What Actually Changed

A technical breakdown of the 2024 OWASP Top 10 updates, what moved, what got added, and what it means for your scanning configuration.

Jul 10, 2024 · Alex Koval

How to Add Security Testing to Your CI/CD Pipeline

Step-by-step guide to integrating SecTests into GitHub Actions, GitLab CI, and Jenkins without adding minutes to your deploy time.

Apr 5, 2024 · Dana Ortiz

SOC 2 Compliance for Startups: What You Actually Need

Cut through the noise. Here is what SOC 2 Type II actually requires, what auditors look for, and how to automate evidence collection.