Learn security

No security background required. Each guide explains one piece of the picture in plain language. What it is, why it matters, where it fits, and the reputable tools that do it. Security controls first, then the compliance and governance questions that decide what to do with what they find.

Start hereThe security controls landscapeA plain-language map of software security and compliance controls, SCA, SAST, DAST, secret scanning, IaC, licenses, and more, and where each one fits in the life of your software.

Or take the short way round: SCASASTSecret scanningVulnerability prioritization

Looking for how to use Draugr rather than what a control is? That's the documentation, each guide here links across to it, and back.

Code & dependencies

Build & artifacts

Running services

Posture & operations

Compliance & governance

Cross-cutting