Company
Date Published
Author
Brian Piper
Word count
1297
Language
English
Hacker News points
None

Summary

Onna Technologies, a data centralization software company, integrates security across every facet of their development process by using Snyk and Sysdig to secure the SDLC while saving time and money. The company's Director of Security, Brent Neal, highlights three vital areas their customers expect them to uphold: privacy of individuals and sensitive information, confidentiality of client data and business activities, and compliance with applicable regulations. Onna uses Snyk for complete container security, improving vulnerability management and prioritization efforts, while Sysdig provides threat detection in the production environment. The company also leverages Snyk's software composition analysis to improve their SDLC by making it more secure. Additionally, Onna has adopted DevSecOps, using tools that integrate security seamlessly into their existing processes and workflows, and has implemented container scanning and static application security testing (SAST) to protect customer data and satisfy internal needs. The Snyk + Sysdig integration is expected to refine the company's shift left approach, reduce costs, deliver products faster, and improve security posture.