Shipping code quickly with confidence: Security Testing
Blog post from Basis Theory
Basis Theory outlines a layered security-testing strategy within its broader “Shipping code quickly with confidence” series, describing how continuous testing during development and continuous monitoring after deployment support its data-tokenization platform. Its approach includes static code scanning and linting for C# code, automated dependency reviews through Dependabot, and container vulnerability scanning with Trivy in GitHub Actions to identify high-severity operating system and library issues. The company also uses dynamic application security testing against APIs and its user portal, updating scans from Swagger specifications after deployments and targeting OWASP Top 10 risks. Beyond the CI/CD pipeline, nightly internal and external network penetration tests seek to detect infrastructure issues such as open ports or routing errors, while independent third-party red teams provide additional assessment of application and system defenses. These security measures complement acceptance, integration, synthetic, and load testing to provide confidence in functionality, availability, performance, and protection against known vulnerabilities and common attack vectors.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.