How Tide transitioned to developer-first security

  • Democratized security with the help of security champions and developers
  • Reduced noise in detecting supply chain vulnerabilities by 80% using Semgrep's reachability analysis
  • Achieved 100% fix rate for issues found using Semgrep's custom rules
Share

In this video case study, Devyani Vij, Sr. Product Security Engineer at Tide, discusses how enables her team to deploy a secure SDLC model that empowers developers to understand security issues and make long term improvements to their coding decisions.

Devyani talks about:

  • Embedding tools in the SDLC process so that each step of SDLC is secured

  • Choosing security products that are developer-first

  • Successfully implementing a Security Champions program, democratizing security and fostering its widespread adoption

  • Reducing false positives in Software Composition Analysis (SCA) by 80% using Semgrep Supply Chain’s reachability analysis

  • Achieving a remarkable 100% fix rate using Semgrep Code’s (SAST) custom rules

  • Leveraging Semgrep Assistant, an AI-powered tool, for enhanced understanding and efficient remediation of vulnerabilities.

  • Implementing Semgrep’s IDE extensions to proactively address security concerns at an early stage, thereby promoting shift-left approach.

Watch the detailed conversation on YouTube.

About

Semgrep enables teams to use industry-leading AI-assisted static application security testing (SAST), supply chain dependency scanning (SCA), and secrets detection. The Semgrep AppSec Platform is built for teams that struggle with noise by helping development teams apply secure coding practices.