Glossary · Static Application Security Testing

SAST

SAST analyzes source code without running it, tracing tainted input from a source to a dangerous sink. Its quality is measured by false-positive discrimination - flagging the real flaw without drowning teams in noise.

How apPosture treats it

apPosture is a self-hosted, proof-based ASPM platform: it confirms findings with real, safe exploits, correlates every source into one risk-weighted posture, and runs entirely inside your infrastructure with a local LLM. See the proof methodology or the platform.

Related terms
DASTSCAFalse positive rate

See it on one of your own apps - live in 30 minutes

From discovery to a proven attack chain. A PoC in your own environment.