Build secure software and web applications
Move from security requirements through safe implementation, browser boundaries, authorization tests, and vulnerability response.
Topic index
Learn how secure software design, browser boundaries, defensive coding, and verification prevent application vulnerabilities.
Topic index
Pomerium can authenticate a request, apply route policy, protect an application entry point, and provide verified identity context. The application still owns input handling, browser controls, object authorization, business invariants, data protection, safe failure, and vulnerability response.
2 learning paths
Move from security requirements through safe implementation, browser boundaries, authorization tests, and vulnerability response.
Learn cryptographic primitives, key systems, data lifecycle controls, storage protection, and migration without inventing protocols.
8 related guides
Turn application risks into testable security requirements, assurance levels, negative tests, and evidence with OWASP ASVS.
Design a webhook, import, preview, or fetch service with strict destination, redirect, credential, egress, and resource policy.
Select a standard construction and define keys, nonces, context, record format, failure behavior, tests, and migration before coding.
Receive, reproduce, triage, remediate, verify, disclose, deploy, and learn from application vulnerability reports.
Choose transport, application, database, filesystem, storage, and in-use protections from the data threat model and key boundary.
Design origins, sessions, cross-origin reads, state changes, frames, messages, and scripts as separate browser security controls.
Verify object, property, action, workflow, tenant, and administrative authorization with a systematic identity and state matrix.
Build typed validation, canonicalization, parameterization, sanitization, and output encoding at every application boundary.
22 related terms
Protect workflow order, object state, quotas, prices, approvals, and other business invariants from valid-looking misuse.
Convert equivalent input representations to one defined form before comparison, validation, authorization, and storage.
Avoid command interpreters and pass fixed executables and validated arguments through structured process APIs with narrow authority.
Grant selected browser origins permission to read cross-origin responses without treating CORS as authentication or request blocking.
Stop another origin from causing an authenticated browser to perform an unwanted state-changing request.
Prevent untrusted data from executing as active browser content through context-aware encoding, safe DOM APIs, and constrained markup.
Validate, transform, store, scan, and serve untrusted files through bounded stages with separate names, origins, and authority.
Prevent HTTP intermediaries from disagreeing about message boundaries, request length, transfer coding, and the start of the next request.
Prevent attacker-controlled data from changing the structure or meaning of a command sent to an interpreter.
Validate syntax and meaning at input boundaries, then encode untrusted data for the exact output interpreter and context.
Prevent spatial, temporal, initialization, and type-safety errors that can corrupt memory, disclose data, or redirect control flow.
Prevent attacker-controlled file names and paths from escaping an approved storage root after decoding and canonical resolution.
Split a service into components with different authority so compromise of one parser or workflow does not grant the complete service privilege.
Prevent security decisions from becoming stale before the protected state change, resource use, or authorization commit completes.
Understand how scheme, host, and port define a browser origin and limit cross-origin reads, script access, and storage.
Fail safely without bypassing controls, exposing sensitive internals, duplicating effects, or leaving partial security state.
Integrate security requirements, design review, safe implementation, verification, release controls, and vulnerability response.
Prevent unsafe defaults, unnecessary features, exposed diagnostics, excessive authority, and configuration drift across environments.
Prevent untrusted input from making a server reach internal services, cloud metadata, local files, or other unapproved destinations.
Keep untrusted values separate from SQL structure with parameterized queries, allowlisted identifiers, and narrow database authority.
Treat serialized objects as untrusted data and prevent input from selecting executable types, constructors, hooks, or object graphs.
Distinguish a software weakness, exploitable vulnerability, exploit path, exposure, and resulting security impact.