gel appsec governance pentest

GEL — Overview

What GEL Is

GEL (Genesys Enterprise Landscape) is an internal developer / application governance platform. It tracks applications, components, ownership, dependencies, and environment representation (Dev / Test / Prod).

GEL is broader than Vault. Vault is a specific secrets-management service; GEL is the platform layer for application lifecycle and security governance.

What GEL Does (High Level)

AreaDescription
Application catalogApplications and components
OwnershipTeams and owners
DependenciesRelationships between components
Environment representationDev / Test / Prod tracking
Security postureSecurity status and scorecards
Deployment governanceIntended security decision point for deployments

Mental Model

Applications → Owners → Components → Snyk → Pentest → ARB → Deployment Gate

Relationship to Vault

Vault is a specific service under security assessment. GEL may eventually consume Vault pentest status as one input to application security gating — but Vault testing methodology and findings live in the Vault notes.

Vault API - Overview · Vault API - Pentest Game Plan > Relationship to GEL

Relationship to GForge / Loom

Note

GForge is described as deployed on GEL. GEL is therefore hosting/platform context for that engagement — GEL itself is not automatically in scope when testing GForge.

GForge - Overview · GForge - Architecture > Network and Hosting Placement

Relationship to Other Systems

See Genesys Security Architecture - Overview for the full system map.

SystemRelationship
SnykAutomated vulnerability / dependency findings
Pentest / Red TeamRuntime / manual security validation
ARBArchitecture Review Board — design / governance compliance
Vault APISpecific service; pentest results may feed GEL
GForge / LoomApplication described as deployed on GEL; separate engagement