Safe Agentic A working canon · v0.27
PL2-sast-dast · Validation

SAST / DAST present.

static and dynamic application security testing with agent-actionable findings; findings, suppressions, and rule disables carry accountability (rationale, named reviewer, expiry where applicable). Tool choice is project-dependent (e.g. Aikido, SonarQube for compliance cases); the concern is coverage across both testing classes, not a specific vendor

Where does your codebase stand?
Click a level to mark your current maturity.