Cookies Notice
This site uses cookies to deliver services and to analyze traffic.
🥇 Frost & Sullivan names Apiiro #1 in innovation for ASPM
Unified risk and vulnerability management across application, infrastructure, and code quality scanners, with code-to-runtime actionable context
Automated security controls validation and assurance based on your organization’s SDLC policies, with actionable context from your CMDB
Risk Graph policy engine and developer’s guardrails at every phase: design, development (pull request), and delivery (build/deploy)
As a payments infrastructure provider, Paddle’s application threat landscape is significant—including all the risks associated with payment security and privacy, as well as the security of the Paddle application itself. As a small application security team building out its AppSec program, Paddle knew they needed a way to multiply their efforts and foster better collaboration with development teams.
Vulnerabilities from their existing tools were being surfaced too late in the SDLC, leading to delayed code releases and internal friction. But collaborating with the developers or engineering teams to address risks was also challenging because they didn’t have insight into who owned what.
Paddle sought a solution to help them adopt a proactive, developer-centric approach to application security and optimize their existing tooling and manual risk assessment processes such as pen tests, security code reviews, and threat modeling.
Paddle rolled out Apiiro in a staged approach to gain visibility across its application estate, use that context to build risk-based policies and developer workflows, and then measure and optimize their program success over time.
Through Apiiro’s easy-to-install GitHub integration, Paddle quickly got a complete inventory across their nearly 500 repositories, including technologies, open source usage, exposed secrets, sensitive data, and development behavior. That visibility, coupled with the ingestion of vulnerability findings from existing tools, gave them an aggregated view of risks. It also enabled them to prioritize based on business impact and risk likelihood and connect risks to their root cause in code and developer owner.
Apiiro also provides a single hub for implementing policy-as-code, helping automate developer guardrails and enforce application security best practices on every pull request. This allows Paddle’s application security team to meet the developers where they’re comfortable with a common taxonomy.
Apiiro’s continuous application inventory, policy-as-code engine, and application risk control plane have acted as a force multiplier for the Paddle application security team.
In addition to leveraging Apiiro’s ASPM to solve their core challenge of enabling a developer-centric approach to security, Paddle saw Apiiro as an opportunity to consolidate and deepen their application security testing coverage.
Paddle now leverages Apiiro’s open source and software supply chain security solutions, giving them fully integrated visibility and risk detection across packages, repositories, and pipelines.
“Since introducing Apiiro’s Software Supply Chain Security (SSCS) at Paddle, we have been able to ensure pipelines are set up securely and have improved insights into the configuration of our source control repositories—a capability not provided by traditional AppSec tools. This heightened visibility, coupled with Apiiro’s risk-based prioritisation and policy engine, instills confidence in our capability to continually measure supply chain risk and assess against best practice moving forward.
– Colin Barr, Senior Engineering Manager – Application Security, Paddle
Paddle is a payments infrastructure provider, enabling software companies to respond faster and more precisely to every growth opportunity.
Industry: B2B Software
Employees: 300+
Developers: 80+
“The unique value that Apiiro provides Paddle is as a force multiplier we can do more with less, we can meet the developers where they’re comfortable, we can provide them the information that they need to fix or to mitigate issues in a single unified view.”
—Jonny Herd, VP of Information Security & Enterprise Technology, Paddle
This site uses cookies to deliver services and to analyze traffic.