Skip to main content
Static application security testing

Static application security testing

Search complete. 11 mentions across 7 episodes found for "Static application security testing".

Sep 9, 2026

Andy HorngoldGUEST
16:22
I think in the new environment, you're able to do things significantly quicker than you were previously.
Andy HorngoldGUEST
16:27
Like, I remember doing pen tests back in the day where you were asked to do source code reviews or at least code-assisted pen tests, and you'd have to use one of the SAST scanners, the static code analysis tools that was out there and was available, but it was always, it was always a headache.
Andy HorngoldGUEST
16:42
I don't think anybody...
Andy HorngoldGUEST
16:43
Like, when I ran a pen testing team over at Context, nobody enjoyed doing that security, like, code review side of things.
Tobias ZimmergrenHOST
34:48
to replace the third-party code scanning tools that we're using right now.
Tobias ZimmergrenHOST
34:51
Because we're using some well-known third-party code scanning tools that have both DAST and SAST, so Static Application Security Testing and Dynamic Application Security Testing.
Tobias ZimmergrenHOST
35:02
And the dynamic one is like, okay, you're running here, let's do a pen test on it.
Tobias ZimmergrenHOST
35:05
And the static one is, okay, here's your code running through a static code analyzer.
Stephen SimsGUEST
19:49
I would say half the floor was like AI SOC.
Stephen SimsGUEST
19:53
And so how do you define your moat or your differentiation to stand out and solve problems? So we currently support like API testing, web app testing, SAST and DAST validation, and then LLM chatbots.
Stephen SimsGUEST
20:08
We believe strongly in like human in the loop and that, and I'll give you a good example.
Stephen SimsGUEST
20:14
We've benchmarked against different solutions out there, both open source and commercial.
James BerthotyGUEST
5:25
And I think year over year, as within the OWASP top 10, we've seen like BOLA and IDOR move up the chart, that this is the opportunity that presents itself is really we're talking about authorization level vulnerabilities from the DAST side.
James BerthotyGUEST
5:41
And then AI SAST to me is the same logic, but applied to like code analysis.
James BerthotyGUEST
5:46
So it's really about getting the maximum value out of like a contextual understanding of your application.
Chris RomeoHOST
5:52
Okay, so does AI pen testing imply agentic? Like, are these things synonymous?

28 MINS LATER

James BerthotyGUEST
33:43
And the question, like, could...
James BerthotyGUEST
33:45
Could OpenAI or Anthropic make a, I'll just use like sneak check marks, whoever, like could they make one of those solutions? Sure.
James BerthotyGUEST
33:53
But I don't like AI SAST, which is what they currently have the closest version of, is still just one slice of the alphabet soup that you named.
James BerthotyGUEST
34:07
And so I just have a hard time believing that they're going to in a timely manner, expand across that entire suite of offerings.
Asaf SaarGUEST
12:54
It changes is how you are looking and defining your, your security strategy, right? How you build a plan, how you are executing at that, and you need to look at from different angle.
Asaf SaarGUEST
13:03
We look at the AppSec, the traditional AppSec with SCA and SAST, right, infrastructure and code containers and such, and then comes the AI capabilities.
Asaf SaarGUEST
13:11
Again, this is runtime.
Asaf SaarGUEST
13:13
It's guardrail, it's, it's red teaming, it's, um, prompt injection and, uh, jailbreaking, right? This is a completely different angle that you need to plan and act upon.
James BerthotyGUEST
6:40
And so I've just been shocked by the number of teams who are willing to rethink their entire security program in light of AI.
James BerthotyGUEST
6:47
They're like, do I even need a SAST SCA scanner? Like, what does a scanner even do now that we're deploying code so quickly in an entirely different way? And it's leading them to rethink almost every aspect of their security program.
James BerthotyGUEST
7:00
And there's such a willingness to throw out old tools, adopt new ones, and figure out the right stack that it's really been pretty crazy to see how quickly it's happened.
Mackenzie JacksonHOST
7:09
And where are you at in that throwing out old tools kind of journey? Because it is something that I think from the vendor perspective, I put my little vendor hat on.
Mackenzie JacksonHOST
7:30
And SaaS is still important.
Mackenzie JacksonHOST
7:31
But I think if we just remove all of that and we had to do it...
Mackenzie JacksonHOST
7:36
Is there still a world where SAST SCA scanning is needed? Is it more important? Is it morphed in? How does that future exist?
James BerthotyGUEST
7:47
It's so much of the goal of Latio as a whole is to provide people tailored recommendations for their environment.
Seth LawHOST
29:41
Go ahead, Ken.
Ken JohnsonHOST
29:43
Just a question around where are the vulnerabilities coming from? Are these like you're doing nightly or weekly scans and these are SCA vulnerabilities or you're doing those same scans in container vulnerabilities or is it SAST vulnerabilities, DAST vulnerabilities? What's kind of the general breakdown that we're talking about?
Jeevan SinghGUEST
30:05
Yeah, it's everything so.
Jeevan SinghGUEST
30:09
Our most is the detections that we have put into place, so we leverage our bug bounty to.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.