From the Labs

Founder perspectives and field insights on AppSec, AI, and compliance.

AI-generated code and the security gap

When the Code Generator Doesn't Know What Secure Looks Like

A new IOActive study quantifies the security gap in AI-generated code: 59% average security performance, 31.6% fully exploitable, near-universal failure on infrastructure code. The numbers confirm what the architecture has been telling us — security can't live inside the generation layer.

Continuous Compliance and Security Assurance

When Compliance Becomes Continuous, or Becomes Fiction

Traditional compliance processes operate on periodic snapshots, but modern systems change continuously. The gap between claimed security posture and actual system behavior is growing — and only continuous assurance can close it.