Category
The bug is still in the code you ship. Encode the sink, check the object, name the finding in the PR. A WAF is not this pillar. Open a shortlist for the buy you are making.
We split XSS defenses by encoding the sink, then Trusted Types. A WAF is time you bought, not this list.
ShortlistsWe split SAST by whether the finding names the sink in the PR. A PDF dump is not a review.
ShortlistsWe split DAST by poking the app you already run. A source scanner is a different list.
ShortlistsWe split secret scanners by whether they catch the next leaked key. A vault is Identity.
ShortlistsWe split authz libraries by the object check in the handler. A role name on a badge is not enough.
More categories
Questions about Application Security
A WAF can buy time. It is not a substitute for encoding the response or checking the object id. WAF lives under Web Security.
No. A finding is a ticket. The object check is in the handler you ship.
Contract lint and fuzz live under API Security. This pillar is the app you compile.