gel appsec governance pentest snyk
GEL — Integrations
How GEL relates to external security and governance systems. Do not present roadmap concepts as already implemented — see status labels.
Integration Map
| Integration | Type | Role |
|---|---|---|
| Snyk | Automated scanning | Code / dependency vulnerability findings |
| Pentest / Red Team | Manual / runtime | Security validation and abuse testing |
| ARB | Governance | Architecture Review Board — design compliance |
| ServiceNow | Workflow | Ticketing / workflow (To Confirm) |
| Red Team AI Workspace | Automation | Future Red Team automation (Planned / Discussed) |
See Genesys Security Architecture - Overview for the full system diagram.
Snyk
Confirmed
Snyk provides automated code and dependency security findings consumed by GEL as part of application security posture.
| Snyk | Manual Pentest | |
|---|---|---|
| Scope | Automated / static — code, dependencies, known patterns | Runtime — authorization, logic, trust boundaries |
| Strength | Breadth, consistency, CI integration | Context-aware abuse, cross-team scenarios, auth flows |
| Limitation | Cannot prove runtime authorization or business logic flaws | Time-bound, requires domain context |
For Vault pentest: Manual testing should not simply re-prove Snyk results. Prioritize:
- Authorization and IDOR/BOLA
- Runtime behavior and trust boundary validation
- Business logic and workflow abuse
- Cross-team isolation
- Authentication and token handling flows
- Abuse scenarios and secret exposure paths
→ Vault API - Test Cases · Vault API - Pentest Game Plan > High-Priority Testing Themes
Note
Snyk integration across the GForge repositories, including the AI Gateway, was described as in progress. Treat it as an active workstream rather than fully deployed coverage. → GForge - Pentest Game Plan > Snyk vs Manual Effort
Red Team / Pentest
Confirmed
Manual / runtime security validation complements Snyk by testing authorization, business logic, and trust boundaries in live systems.
- Pentest status may be recorded in GEL as part of application security posture.
- Findings may influence GEL security gate decisions (see GEL - Security Model > Gate Logic (Anticipated)).
Vault engagement: Primary pentest target is the Vault API itself.
→ Vault API - Pentest Game Plan · Vault API - Findings
ARB (Architecture Review Board)
Confirmed
ARB provides architecture, design, and governance compliance review. ARB status is an anticipated input to GEL security gating.
To Confirm
- How is ARB status recorded in GEL today?
- Is missing ARB review a current deployment blocker?
ServiceNow
To Confirm
Ticketing / workflow integration with GEL — not documented in available notes. Confirm whether ServiceNow is connected and for what workflows.
Red Team AI Workspace
Planned / Discussed
Future automation for Red Team workflows. Not confirmed as implemented. Confirm roadmap status during kickoff.
Vault API (as GEL Input)
Inferred
Vault is a specific service under assessment. GEL may eventually consume Vault pentest results as one security signal — similar to Snyk and ARB inputs.
Vault pentest documentation lives separately:
→ Vault API - Overview · Vault API - Findings
Do not duplicate Vault testing methodology here.
GForge / Loom (as Hosted Application)
Confirmed
GForge is described as deployed on GEL. GEL provides hosting/platform context for the GForge engagement.
Warning
GEL is not automatically in scope when testing GForge. Keep the platform boundary distinct from the application under test.
GForge documentation lives separately:
→ GForge - Overview · GForge - Architecture > Network and Hosting Placement