| Primary category | Application Security Posture Management (ASPM) | Release-evidence verification |
| Core workflow | Aggregate, correlate, and prioritize application-security risk based on code and business context | Qualify evidence and evaluate against versioned policy |
| Evidence model | Risk score, exposure context, and remediation state | Corroboration, freshness, policy-version binding |
| Release-decision support | Informs prioritization and remediation before release | Determines whether evidence satisfies policy |
| AI/coding-agent governance | May surface AI-generated findings within risk workflows | Agent-neutral governance across IDEs, MCP servers, repos, CI, cloud, and runtime |
| Runtime context | May include runtime signals in risk scoring | Runtime-correlated prioritization with evidence that risk was retired |
| Remediation proof | Tracks remediation state and ticket closure | Validated fixes, not just ticket closure |