The ASPM company Apiiro today announced a new feature that shifts risk detection further left, all the way to the design phase. 

Rather than waiting for development to start to find risks, the new Risk Detection at the Design Phase feature uses AI to analyze feature designs for risk.

This includes things related to:

  • Generative AI technology and associated tools, frameworks, technologies, and data exposed to them
  • Handling of sensitive data as part of the application data flow, changing encryption mechanisms, data migrations, writing sensitive data to logs, and using sensitive data as an API return type
  • Architecture design, such as requests for changes in APIs, network, databases, web servers, web clients, logging, serialization, and other component configurations 
  • User authentication and authorization, login processes, and user permissions
  • Third-party integrations and software supply chain

When Risk Detection at the Design Phase detects a risk in one of those areas, it then maps that risk to specific code commits, repositories, and pull requests to paint a picture of how risks might manifest. 

It also generates contextual questions that can be used during a security review, as well as uses the STRIDE model to develop threat stories. 

According to Apiiro, this new feature will enable teams to more proactively mitigate security risks and save on development resources before time is spent working on features that may have to come out due to risk.

“Building secure software starts with secure design, and the new AI-Driven Risk Detection at Design Phase from Apiiro takes the ‘shift left’ approach a step further, addressing risks even before a single line of code is written,” Moti Gindi, chief product officer at Apiiro. “This first-of-its-kind functionality leverages the power of AI to ensure customers have the context required to facilitate efficient security reviews and evolve from a reactive to a proactive approach to application security.”


You may also like…

Q&A: The disconnect between the C-Suite and IT practitioners on AI readiness

Securing client-facing apps in a hostile, risk-filled 21st century