Kangl Pipeline Security Runtime is the managed execution layer that applies security controls across eligible Azure DevOps build pipelines. It gives AppSec and platform teams one runtime state for coverage, policy enforcement, emergency control, synchronization, and audit instead of asking every team to maintain its own integration.
How the Security Runtime works
The Security Runtime is configured centrally and applies the appropriate security provider during eligible pipeline execution. Underneath, Azure DevOps Pipeline Decorator is one implementation mechanism used to place steps into applicable YAML and classic build jobs. That technical detail stays behind the product surface; teams operate the Runtime, not the injection primitive.
Why it matters for security
- Coverage by default: new pipelines are covered from their first run.
- No YAML sprawl: one implementation instead of hundreds of copies.
- Exclusion becomes visible: opting out is a governable act, not a silent omission.
The operational requirements
Organization-wide execution creates organization-wide responsibility. Safe operation needs central settings, a global kill switch, per-pipeline enable/disable state, drift detection, and an audit trail — all first-class Security Runtime controls.

