What really is application security (appsec)?
What appsec covers, and why it isn't a compliance checklist
This is the beginning to my series in breaking down application security so that anyone can do it without hiring expensive teams of employees. We start by defining what appsec really is!
There’s no place like home?
Imagine you just bought a home. It has a fancy kitchen, beautiful living room, a cozy den, a yard for your dogs, and spacious bedrooms. You’re living the life in your new home! You’re cooking in the kitchen, enjoying nice sunsets, your dogs love the yard, you can relax at night with some TV or quietly read a book in your den. Then after a few weeks, you realize you have to mow the lawn! Then another couple of weeks, a light bulb goes out. Then the next day, your ceiling fan won’t turn on.
As time goes on, you realize that you’re spending more and more time on home maintenance, and you’re finding less and less time to enjoy your newly bought home! One day, the unthinkable happens. Your home’s pipe burst and has been flooding without you noticing for a few hours, on the other side of the home from you.

Well, that’s the reality of every home owner and application owner. After you’ve released your application to the world, the world starts finding that a part of your application is buggy, so you go target a fix there. Your application crashes the next week, so you have to go investigate and fix it asap because time = money and you want your application up at all times! Then one day, to your horror, you realize that your application has been breached and your company’s data is being leaked.
Appsec is not a checklist
Your home is constantly evolving. There are many pieces of hardware (and maybe software??) that make your home whole. Everything from your utility infrastructure (electrical, water, sewage, etc.) to your home exterior, yard, and even your tools have to be maintained correctly. You have to know all the different parts that make up your home, go around seeing if anything is “off”, testing to see if certain stresses hold, fixing broken parts with the correct replacement part, and re-testing to see if you’ve fixed it properly and monitoring afterwards. Many will have you believe that inspection just has to be done once in a while, but to maintain your home properly, you must be proactive.
Much like your home, your application is constantly evolving to your business and customer needs, and so appsec must be a part of any application maintenance.
Appsec is a process of understanding all the components that make up your application, careful observation, testing, detailed reporting, surgical fixes, and re-testing to ensure correctness. It is not about a list of things one checks off that many will have you believe. I’m 👀-ing at you compliance (though no shade because compliance is genuinely needed to prove to other companies and auditors that you are doing the right things for your customers)!

And basically you’re right. It is quite complicated to the everyday business owner who wants to focus on growing their business, but it’s genuinely worth it in the long run.
Application Security is more than tools or a bunch of people
My experience as a security engineer at Amazon taught me three really important lessons.
Companies promise you a lot, and deliver little: Tools you buy from vendors may help you solve parts of a problem, but it won’t solve the problem itself, magically.
Humans use of tooling is imperfect: Engineers can use a bunch of tooling, but it does not mean they are using it to its full potential. I’ve seen engineering teams buy a ton of tooling only to use 10-50% of its capabilities and try to augment those “missing” capabilities with other bought tooling. It just becomes really expensive for no reason.
Trust your experts and automate around their insights: Trusting the people who understand the problem and either carefully designing tools around their insights or letting them use their custom tools to help solve parts of the problem, will carry you further than assigning a big group of people to solve the problem.
Going back to our home analogy, these can be understood as:
Automatic Vacuums promise a cleaner home, but it does not promise you a clean home. It’s not going to declutter the floor or navigate in between your dining chairs. Its executive function is to just vacuum open space.
Imagine you bought a full snap-on toolsetand used maybe the hammer and screw driver.
Instead of hiring a large group of guards to sit outside at all times preventing trouble it’d be better to hire an expert to install automated smart locks, motion lights, and cameras that alert your phone instantly.

Over time your company will grow. Your hires will continue, but having the right group of people who have the experience and custom built tooling to tackle the problem at hand will prove in dividends over the long run. This can be in the form of your own dedicated cyber security staff building or buying tooling, your developers using security features of tooling (think AI code harnesses like Claude Code or Codex), or cybersecurity professional services who come in and do the work for you.
Whatever form your appsec program looks like in the long run, it’s important to remember the above lessons as they are lessons to be learned at Amazon as well. You’re not alone!
Just tell me what appsec consists of
Well it’s hard to pinpoint as many organizations and security professionals argue what the scope of appsec is. Some consider code analysis to be the extent, others argue that isn’t enough and we have to go much further into testing, others argue that cloud security (cloudsec) is a part of appsec as that is where applications live.
So obviously when I define it, it might ruffle some feathers, and that’s okay! It’s okay to argue what the boundaries are, so long as you make it clear to the leadership you report to that this is the boundary of the problem that you are willing to own and secure. And if you’re a company without dedicated security staff, I may encourage you to adopt the scope that I present below.
I define it as I defined it above.
Appsec is a process of understanding all the components that make up your application, careful observation, testing, detailed reporting, surgical fixes, and re-testing to ensure correctness.
To do really good application security you can break down the process like this:
Work with the application developer team to really understand what the application consists of and what each part is supposed to do. The intent always matters. Each route of a web application serves a purpose and to understand what it’s supposed to do can give you some context on what we shouldn’t be expecting. If things are unclear, just ask!
The careful observation part is to observe in your application code the following:
How untrusted input (aka sources) can flow into potentially dangerous functions in your code (aka sinks) where hackers can manipulate and proxy requests to place malformed input.
You can also assess things like authN/Z (identity and authorization). These are fancy words for understanding what parts of the application should have a check on who can access those parts, and what data they can interact with. For instance, if you had an admin endpoint, you want only specific authorized individuals to access that endpoint.
Business logic flaws are also quite tricky, but part of really good appsec is trying to resolve flaws such as infinite coupon generation (you just unintentionally discounted your own revenue stream) or unintentional PII (personally identifiable information) leaks which carry with it legal consequences, and many other variants that are specific to your business logic.
Model what the threats are based on your understanding of the above
Test your app with the context above to prove that your suspicions hold
Report comprehensively what your findings are so you can keep a record of what you’ve found, how you can replicate your finding, what is the impact of the vulnerability and the extent of what you can do with this, and how to fix for the developers.
Fix the proven vulnerabilities from your test. It’s important that you don’t just identify the problems and keep building. It’s important to fix them with the appropriate urgency.
Re-test to validate that you fixed it completely.
The definition of the appsec workflow I define is important to me because of a few things:
It’s important to have proper context of the application in the first place. Many security engineers rush into the process of taint analysis and testing, but without understanding the app, how are you going to find the flaws that seem benign like infinite use coupon codes? To really be able to maintain an application properly, you really must know the ins and outs of an application.
Testing as part of the workflow to prove vulnerabilities allows you to hold a stance that these are vulnerabilities worth fixing. It’s no longer just theory.
Reporting is important both from the perspective of giving your developers enough information to fix the code properly AND it is essential to proving to your business stakeholders, customers, and other governing bodies that you’re taking security seriously. It can help you over time increase the trust of your customers and business!
There’s a lot to unpack here and I really did try above, but I’ll reserve the finer details in more posts. Stay tuned!
P.S. 8/18/26: I found a video herethat does a great job explaining the above simply as well. Fantastic account that explains concepts very well!
Pigeon is a NYC Cybersecurity Services company, specializing in Application Security. If you or anyone you know needs application security services, please reach out to me at david@pigeonlabs.ai. We’re willing to work with you near and far!
Subscribe to Breadcrumbs
New field notes on appsec and AI agent security. Free — unsubscribe anytime.
