Lightning Jar - Web Studio Lightning Jar Wordmark
Skip to main content
Technologies

Snyk

Developer Security Platform · Commercial (free tier available)

We use Snyk to find and fix known vulnerabilities across the stack—open-source dependencies (SCA), first-party code (SAST), containers, and infrastructure as code—mapped against its curated vulnerability database.

Snyk integrates with the repository and CI/CD, opening automated fix pull requests and enforcing license and security policy gates without slowing delivery.

Visit Snyk →

How We Use It

  • Dependency (SCA) vulnerability scanning with automated fix PRs
  • Static analysis (SAST) of first-party code in CI
  • Container image and infrastructure-as-code misconfiguration scanning

Auth & Security

Why this matters: Security is trust—modern auth and session practices protect users and keep compliance teams comfortable. Security is foundational. We standardize on modern auth, strong session management, and defense-in-depth controls to protect users and systems. Preferred defaults: BetterAuth for app auth, token-based sessions with rotation, 2FA (TOTP + WebAuthn), Arcjet for edge protection.