KANGL LEARN

AppSec concepts, in plain language.

Short, honest explainers on the concepts behind application security operations — from SAST and SCA to Pipeline Security Runtime, policy as code, and drift. Written for developers and platform engineers, free of vendor fog.

CONCEPTS

ASPM

What is ASPM (Application Security Posture Management)?

ASPM platforms aggregate findings from security tools into unified risk views. Learn what ASPM does, its limits, and how it differs from a control plane.

Read →
Security Control Plane

What is a Security Control Plane?

A control plane holds desired state and reconciles reality against it. Learn what the pattern means for application security operations.

Read →
Shift-Left

What is Shift-Left Security?

Shift-left moves security feedback earlier in development. Learn what it means in practice, where it went wrong, and what 'shift left, govern centrally' looks like.

Read →
SBOM

What is an SBOM (Software Bill of Materials)?

An SBOM lists every component in your software. Learn the formats, the regulatory push, and what makes SBOMs useful rather than ceremonial.

Read →
CVSS & Severity

CVSS and Severity Levels, Explained

Critical, high, medium, low — where severity ratings come from, what CVSS measures, and why cross-tool severity needs normalization.

Read →
Policy as Code

What is Policy as Code?

Policy as code expresses rules as versioned, evaluable artifacts instead of console settings. Learn the pattern and its application to AppSec enforcement.

Read →
Supply Chain Security

What is Software Supply Chain Security?

Supply chain security covers everything between a developer's keyboard and production: dependencies, build systems, and pipelines. Learn the attack surface and defenses.

Read →
Multi-Tenancy

What is Multi-Tenancy (and Row-Level Security)?

Multi-tenant systems serve many isolated customers from one deployment. Learn the isolation models and why database-enforced boundaries beat application conventions.

Read →
DevSecOps

What is DevSecOps?

DevSecOps integrates security into the DevOps lifecycle as a shared, automated practice. Learn the principles and the operational layer that makes them stick.

Read →
CI/CD Security

What is CI/CD Security? A Practical Guide

CI/CD security protects source, build pipelines, credentials, dependencies, and release paths. Learn the controls that matter and how to keep them enforced.

Read →

SECURITY OPERATIONS, UNIFIED

Bring your security tools.
Kangl makes them one platform.

Start with seven days of full plan access — or see it live with our team first.