THANK YOU FOR SUBSCRIBING
Development and security teams may now handle the most significant software supply chain issues from code to runtime in a proactive manner.
FREMONT, CA: "Other vendors miss a piece of the equation," says Amir Jerbi, CTO and co-founder of Aqua Security. "For example, some solutions focus on the build while others focus on the code and build, but Aqua is the only solution that allows developers to offer proactive security measures across code, build, deploy, and runtime phases. With this, we are giving developers and security teams the confidence to continue to build their cloud native application development capabilities and prevent supply chain attacks." Aqua Security, the premier pure-play supplier of cloud-native security, has developed the industry's first and only complete software supply chain security solution. The new solution protects throughout the full software development lifecycle (SDLC) and assists enterprises in proactively preventing and stopping supply chain assaults on cloud-native apps.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Aqua data indicates a 300 percent increase year-over-year in the number of software supply chain threats. Increasing dangers are now recognized as a security concern by foreign governments; most recently, the White House issued an executive order to boost software supply chain security from the development stage.
Aqua recognizes software supply chain risks as threats from third-party artifacts, open-source dependencies, and hostile actors aiming to compromise the developer's unique toolset and environment. Aqua is providing new features to its existing supply chain solution to fight the growing risk to the software supply chain. Aqua is the only solution on the market that safeguards against supply chain risk from code to runtime, covering both the application and underlying infrastructure, thanks to these new capabilities.
IBM's Systems Sciences Institute claimed, "It is six times more expensive to correct a bug discovered after implementation than one discovered during design. Also, fixing bugs found during testing could cost 15 times more than fixing bugs found during the design phase. The Aqua Software Supply Chain Security Solution delivers alerts and acceptance gates across the code. It builds phases to decrease risk early in the development lifecycle proactively. These assurance policies can be automated, eliminating feedback loops for development and security teams and eradicating these costs.
"Attackers are targeting the source code and its dependencies as a way to inject vulnerabilities and backdoors to applications. Aquas assurance policies apply proactive security on your software supply chain process and its outcome, identifying and mitigating such risks," says Joseph Elbaz, head of application security at Grubhub. "This is exactly what is needed to ensure your release quality."
The solution is a component of the Aqua Platform's fully integrated Cloud Native Application Protection Platform (CNAPP). Aqua redefines the CNAPP category with more integration and end-to-end protection as the first CNAPP to offer a supply chain solution. The Aqua Supply Chain Solution includes new robust features—code scanning, CI/CD posture management, pipeline security, next-generation SBOM, and open-source health assessment.
"The Aqua Platform is undoubtedly the most robust CNAPP in the industry. Adding these new Software Supply Chain Security capabilities to our existing Dynamic Threat Analysis and runtime protection capabilities, we bring the most proactive and holistic defense-in-depth solution that can secure from day one and stop cloud native attacks," says Jerbi.
More in News