THE KANGL BLOG

Operating AppSec, written down.

Practical guides for the unglamorous layer where security programs succeed or fail: coverage, drift, policy, credentials, audit, and scale — across Azure DevOps estates.

Snyk · Azure DevOps

Snyk and Azure DevOps: Integration, Enforcement, and Scale

How to run Snyk in Azure DevOps pipelines, choose between pipeline tasks and centralized injection, protect credentials, and keep coverage from drifting.

Aug 26, 2026 · 9 min read
Read the article →
Azure DevOps · Pipeline Security

Azure DevOps Pipeline Security Checklist: 15 Controls That Matter

A practical Azure DevOps pipeline security checklist covering identities, service connections, branch policies, scanners, gates, drift, and audit evidence.

Aug 25, 2026 · 10 min read
Azure DevOps · Best Practices

Azure DevOps Security Best Practices for 2026

A practical checklist for securing Azure DevOps organizations, projects, repositories, service connections, and build pipelines — and how to keep it enforced.

Aug 18, 2026 · 9 min read
Managed Pipelines · Enforcement

How to Enforce Security Scanning Across Hundreds of Azure DevOps Pipelines

Copy-pasting scan tasks into YAML does not scale. Here is an operating model for rolling out and enforcing security scanning across a large Azure DevOps estate.

Aug 11, 2026 · 8 min read
Drift · Managed Pipelines

Configuration Drift: Why Pipelines Quietly Stop Scanning

Security tasks disappear from CI pipelines without anyone deciding to remove them. Here is why drift happens, why it goes unnoticed, and how to close the loop.

Aug 4, 2026 · 7 min read
Policy · Architecture

Backend-Authoritative Policy: Why UI Toggles Are Not Governance

If a policy decision is computed in a browser or a YAML file, it is advice. Real enforcement needs one authoritative evaluation point in the backend.

Jul 28, 2026 · 6 min read
Snyk · Operations

Operating Snyk at Enterprise Scale on Azure DevOps

Snyk finds the vulnerabilities. Operating Snyk across a large Azure DevOps estate — projects, Security Runtime, pipelines, service connections — is its own discipline.

Jul 21, 2026 · 8 min read
Azure DevOps · Security Runtime

Kangl Pipeline Security Runtime: Coverage Without YAML Sprawl

Pipeline Security Runtime applies security controls across Azure DevOps builds without repetitive YAML edits. Learn how coverage, control, and drift repair work at scale.

Jul 14, 2026 · 7 min read
Azure DevOps · Coverage

YAML vs Classic Pipelines: Closing the Security Coverage Gap

Most estates still run both YAML and classic build pipelines. A security rollout that only handles one of them leaves a permanent blind spot.

Jul 7, 2026 · 6 min read
Policy · Developer Experience

Fail the Build or Monitor Only? Designing Thresholds Developers Accept

Blocking every finding halts delivery; blocking nothing is theater. How to design severity thresholds and enforcement modes that survive contact with real teams.

Jun 30, 2026 · 7 min read
Posture · Architecture

Normalized Security Posture: Comparing Findings Across Different Scanners

Every scanner counts severity differently. Without a normalized read model, 'what is our posture?' has a different answer per vendor console.

Jun 23, 2026 · 6 min read
Strategy · Tool Sprawl

AppSec Tool Sprawl: Consolidating Operations Without Replacing Scanners

The answer to five security consoles is rarely a sixth scanner. Consolidate the operating model, keep the engines.

Jun 16, 2026 · 6 min read
Multi-Tenant · Architecture

Multi-Tenant AppSec: Governing Many Organizations Without Merging Them

Platform teams, MSPs, and holding companies run security across many Azure DevOps organizations. Central control and tenant isolation must both be true.

Jun 9, 2026 · 7 min read
Secrets · Security

Keeping Provider Credentials Out of Pipelines, Queues, and Logs

Scanner tokens are production credentials. The integration architecture decides whether they leak into build logs, queue messages, and variable groups.

Jun 2, 2026 · 6 min read
Audit · Compliance

Audit Trails for AppSec Operations: What Compliance Actually Needs

Scanner reports show findings. Auditors ask about operations: who changed the policy, who disabled scanning, and when. Most stacks cannot answer.

May 26, 2026 · 6 min read
Azure DevOps · Secrets

Service Connections: The Quietest Privilege in Azure DevOps

Service connections hold cloud and vendor credentials behind a friendly UI. Governing them is core AppSec work, not platform housekeeping.

May 19, 2026 · 6 min read
Azure DevOps · Secrets

Variable Groups and the Slow Leak of Pipeline Secrets

Variable groups make sharing configuration easy — including configuration that should never have been shared. A field guide to cleaning up.

May 12, 2026 · 5 min read
Rollout · Strategy

The Org-Wide Scanner Rollout Playbook: From Pilot to Default

A phased sequence for taking SAST/SCA from one pilot team to organization-wide default — without a developer revolt or a coverage mirage.

May 5, 2026 · 8 min read
Operations · Security Runtime

The Global Kill Switch: Change Control for Security Automation

When injected security steps misbehave at 2 a.m., you need one governed switch — not a hundred YAML reverts. Why every enforcement system needs an emergency brake.

Apr 28, 2026 · 5 min read
Strategy · Provider-Neutral

Provider-Neutral AppSec: Keeping the Freedom to Change Scanners

Scanner switching costs are mostly operational, not contractual. A provider-neutral control layer keeps your estate portable.

Apr 21, 2026 · 6 min read
Metrics · Posture

Measuring AppSec Coverage: The Metrics That Survive an Audit

Vulnerability counts fluctuate with scanner behavior. Coverage, enforcement, drift, and freshness are the metrics that describe whether your program works.

Apr 14, 2026 · 6 min read
Policy · Azure DevOps

PR Gates vs Build Gates in Azure DevOps: Where Should Security Decide?

Pull request checks catch issues before merge; build gates catch them before artifacts ship. Mature programs use both — with one policy brain behind them.

Apr 7, 2026 · 7 min read
Drift · Operations

Drift Detection and Force Sync: The Reconciliation Loop for Pipeline Security

Infrastructure teams solved drift with reconciliation years ago. Pipeline security configuration deserves the same loop: desired state, observed state, controlled repair.

Mar 31, 2026 · 6 min read
Policy · Architecture

From Findings to Decisions: The Missing Layer Between Scanners and Builds

Scanners produce findings. Builds need decisions. The translation between them — policy — deserves to be a system, not a convention.

Mar 24, 2026 · 6 min read
Strategy · Kangl

Why Kangl Exists: The Case for an AppSec Control Plane

The origin logic of Kangl: scanners multiplied, Azure DevOps estates grew, and the operating layer between them never got built. So we built it.

Mar 17, 2026 · 7 min read
Coverage · Azure DevOps

Shadow Pipelines: Finding the Builds Your Security Program Forgot

Every estate has pipelines nobody remembers creating — still building, still deploying, never scanned. Here is how they accumulate and how to bring them in.

Mar 10, 2026 · 6 min read

SECURITY OPERATIONS, UNIFIED

Bring your security tools.
Kangl makes them one platform.

Start with seven days of full plan access — or see it live with our team first.