gel appsec governance pentest snyk

GEL — Integrations

How GEL relates to external security and governance systems. Do not present roadmap concepts as already implemented — see status labels.


Integration Map

IntegrationTypeRole
SnykAutomated scanningCode / dependency vulnerability findings
Pentest / Red TeamManual / runtimeSecurity validation and abuse testing
ARBGovernanceArchitecture Review Board — design compliance
ServiceNowWorkflowTicketing / workflow (To Confirm)
Red Team AI WorkspaceAutomationFuture Red Team automation (Planned / Discussed)

See Genesys Security Architecture - Overview for the full system diagram.


Snyk

Confirmed

Snyk provides automated code and dependency security findings consumed by GEL as part of application security posture.

SnykManual Pentest
ScopeAutomated / static — code, dependencies, known patternsRuntime — authorization, logic, trust boundaries
StrengthBreadth, consistency, CI integrationContext-aware abuse, cross-team scenarios, auth flows
LimitationCannot prove runtime authorization or business logic flawsTime-bound, requires domain context

For Vault pentest: Manual testing should not simply re-prove Snyk results. Prioritize:

  • Authorization and IDOR/BOLA
  • Runtime behavior and trust boundary validation
  • Business logic and workflow abuse
  • Cross-team isolation
  • Authentication and token handling flows
  • Abuse scenarios and secret exposure paths

Vault API - Test Cases · Vault API - Pentest Game Plan > High-Priority Testing Themes

Note

Snyk integration across the GForge repositories, including the AI Gateway, was described as in progress. Treat it as an active workstream rather than fully deployed coverage. → GForge - Pentest Game Plan > Snyk vs Manual Effort


Red Team / Pentest

Confirmed

Manual / runtime security validation complements Snyk by testing authorization, business logic, and trust boundaries in live systems.

Vault engagement: Primary pentest target is the Vault API itself.

Vault API - Pentest Game Plan · Vault API - Findings


ARB (Architecture Review Board)

Confirmed

ARB provides architecture, design, and governance compliance review. ARB status is an anticipated input to GEL security gating.

To Confirm

  • How is ARB status recorded in GEL today?
  • Is missing ARB review a current deployment blocker?

ServiceNow

To Confirm

Ticketing / workflow integration with GEL — not documented in available notes. Confirm whether ServiceNow is connected and for what workflows.


Red Team AI Workspace

Planned / Discussed

Future automation for Red Team workflows. Not confirmed as implemented. Confirm roadmap status during kickoff.


Vault API (as GEL Input)

Inferred

Vault is a specific service under assessment. GEL may eventually consume Vault pentest results as one security signal — similar to Snyk and ARB inputs.

Vault pentest documentation lives separately:

Vault API - Overview · Vault API - Findings

Do not duplicate Vault testing methodology here.


GForge / Loom (as Hosted Application)

Confirmed

GForge is described as deployed on GEL. GEL provides hosting/platform context for the GForge engagement.

Warning

GEL is not automatically in scope when testing GForge. Keep the platform boundary distinct from the application under test.

GForge documentation lives separately:

GForge - Overview · GForge - Architecture > Network and Hosting Placement