Skip to main content

Topic index

Software and Application Security

Learn how secure software design, browser boundaries, defensive coding, and verification prevent application vulnerabilities.

Topic index

Understand this domain

Pomerium coverage

Pomerium can authenticate a request, apply route policy, protect an application entry point, and provide verified identity context. The application still owns input handling, browser controls, object authorization, business invariants, data protection, safe failure, and vulnerability response.

Limits

  • An authenticated route does not make the application code or its dependencies safe.
  • A web application firewall or input filter cannot replace parameterization, contextual encoding, object authorization, or safe APIs.
  • A passing scanner does not prove that business logic, alternate paths, state transitions, and exceptional conditions are secure.

Primary sources

2 learning paths

Paths for this topic

8 related guides

Guides in this topic

22 related terms

Concepts in this topic

Software and Application Security

Business Logic Abuse

Protect workflow order, object state, quotas, prices, approvals, and other business invariants from valid-looking misuse.

Learn this term
Software and Application Security

Canonicalization

Convert equivalent input representations to one defined form before comparison, validation, authorization, and storage.

Learn this term
Software and Application Security

Command Injection

Avoid command interpreters and pass fixed executables and validated arguments through structured process APIs with narrow authority.

Learn this term
Software and Application Security

Cross-Site Scripting (XSS)

Prevent untrusted data from executing as active browser content through context-aware encoding, safe DOM APIs, and constrained markup.

Learn this term
Software and Application Security

File Upload Security

Validate, transform, store, scan, and serve untrusted files through bounded stages with separate names, origins, and authority.

Learn this term
Software and Application SecurityStandards and Protocols

HTTP Request Smuggling

Prevent HTTP intermediaries from disagreeing about message boundaries, request length, transfer coding, and the start of the next request.

Learn this term
Software and Application Security

Injection

Prevent attacker-controlled data from changing the structure or meaning of a command sent to an interpreter.

Learn this term
Software and Application Security

Memory Safety

Prevent spatial, temporal, initialization, and type-safety errors that can corrupt memory, disclose data, or redirect control flow.

Learn this term
Software and Application Security

Path Traversal

Prevent attacker-controlled file names and paths from escaping an approved storage root after decoding and canonical resolution.

Learn this term
Platform and Component SecuritySoftware and Application Security

Privilege Separation

Split a service into components with different authority so compromise of one parser or workflow does not grant the complete service privilege.

Learn this term
Software and Application Security

Race Condition and TOCTOU

Prevent security decisions from becoming stale before the protected state change, resource use, or authorization commit completes.

Learn this term
Software and Application Security

Same-Origin Policy

Understand how scheme, host, and port define a browser origin and limit cross-origin reads, script access, and storage.

Learn this term
Software and Application Security

Secure Error Handling

Fail safely without bypassing controls, exposing sensitive internals, duplicating effects, or leaving partial security state.

Learn this term
Software and Application Security

Security Misconfiguration

Prevent unsafe defaults, unnecessary features, exposed diagnostics, excessive authority, and configuration drift across environments.

Learn this term
Software and Application Security

SQL Injection

Keep untrusted values separate from SQL structure with parameterized queries, allowlisted identifiers, and narrow database authority.

Learn this term
Software and Application Security

Unsafe Deserialization

Treat serialized objects as untrusted data and prevent input from selecting executable types, constructors, hooks, or object graphs.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo