KANGL LEARN
AppSec concepts, in plain language.
Short, honest explainers on the concepts behind application security operations — from SAST and SCA to Pipeline Security Runtime, policy as code, and drift. Written for developers and platform engineers, free of vendor fog.
SCANNING & DETECTION
What is SAST (Static Application Security Testing)?
SAST analyzes source code for security flaws without executing it. Learn how static analysis works, where it fits in CI/CD, and its strengths and limits.
Read →SCAWhat is SCA (Software Composition Analysis)?
SCA identifies open-source dependencies and their known vulnerabilities and licenses. Learn how dependency scanning works and why coverage matters more than tooling.
Read →DASTWhat is DAST (Dynamic Application Security Testing)?
DAST tests running applications from the outside, like an attacker would. Learn how dynamic testing complements static analysis.
Read →Secrets ScanningWhat is Secrets Scanning?
Secrets scanning detects credentials committed to code — API keys, tokens, passwords. Learn detection approaches and why prevention beats revocation.
Read →AZURE DEVOPS
What is Kangl Pipeline Security Runtime?
Kangl Pipeline Security Runtime applies security controls across Azure DevOps pipelines without repetitive YAML edits. Learn what it does and how it stays governed.
Read →PR GateWhat is a PR Gate (Branch Policy Check)?
PR gates block merges until required checks pass. Learn how Azure DevOps branch policies work and how security checks fit into pull requests.
Read →Service ConnectionWhat are Azure DevOps Service Connections?
Service connections store the credentials pipelines use to reach clouds and services. Learn how they work and why they deserve credential-grade governance.
Read →Branch PoliciesAzure DevOps Branch Policies, Explained
Learn how Azure DevOps branch policies protect main branches with reviewers, build validation, status checks, and controlled bypass permissions.
Read →OPERATIONS
What is Configuration Drift?
Drift is the gap between intended configuration and reality. Learn why security configuration drifts in CI/CD and how reconciliation loops close the gap.
Read →Vulnerability ManagementWhat is Vulnerability Management?
Vulnerability management is the lifecycle from discovery to remediation. Learn the stages and why the quality of upstream scanning coverage decides everything downstream.
Read →Kill SwitchWhat is a Kill Switch in Security Automation?
A kill switch disables automation estate-wide in one governed action. Learn why enforcement systems need an emergency brake and what a good one looks like.
Read →False PositivesFalse Positives in AppSec: Managing the Noise
False positives erode trust in security tooling faster than anything else. Learn why they happen and the governance patterns that keep noise from killing enforcement.
Read →Security GateWhat is a Security Gate in CI/CD?
A CI/CD security gate turns scan results into a release decision. Learn the difference between PR gates, build gates, thresholds, and monitor-only policies.
Read →CONCEPTS
What is ASPM (Application Security Posture Management)?
ASPM platforms aggregate findings from security tools into unified risk views. Learn what ASPM does, its limits, and how it differs from a control plane.
Read →Security Control PlaneWhat is a Security Control Plane?
A control plane holds desired state and reconciles reality against it. Learn what the pattern means for application security operations.
Read →Shift-LeftWhat is Shift-Left Security?
Shift-left moves security feedback earlier in development. Learn what it means in practice, where it went wrong, and what 'shift left, govern centrally' looks like.
Read →SBOMWhat is an SBOM (Software Bill of Materials)?
An SBOM lists every component in your software. Learn the formats, the regulatory push, and what makes SBOMs useful rather than ceremonial.
Read →CVSS & SeverityCVSS and Severity Levels, Explained
Critical, high, medium, low — where severity ratings come from, what CVSS measures, and why cross-tool severity needs normalization.
Read →Policy as CodeWhat is Policy as Code?
Policy as code expresses rules as versioned, evaluable artifacts instead of console settings. Learn the pattern and its application to AppSec enforcement.
Read →Supply Chain SecurityWhat is Software Supply Chain Security?
Supply chain security covers everything between a developer's keyboard and production: dependencies, build systems, and pipelines. Learn the attack surface and defenses.
Read →Multi-TenancyWhat is Multi-Tenancy (and Row-Level Security)?
Multi-tenant systems serve many isolated customers from one deployment. Learn the isolation models and why database-enforced boundaries beat application conventions.
Read →DevSecOpsWhat is DevSecOps?
DevSecOps integrates security into the DevOps lifecycle as a shared, automated practice. Learn the principles and the operational layer that makes them stick.
Read →CI/CD SecurityWhat is CI/CD Security? A Practical Guide
CI/CD security protects source, build pipelines, credentials, dependencies, and release paths. Learn the controls that matter and how to keep them enforced.
Read →
SECURITY OPERATIONS, UNIFIED
Bring your security tools.
Kangl makes them one platform.
Start with seven days of full plan access — or see it live with our team first.
