Resources · Research Articles

Application security insights.
Evidence for better decisions.

Insights from QFinch on assessment evidence, application context and remediation planning.

QFinch insight

An SBOM finding needs application context

A component inventory is a starting point for investigation. It is not the conclusion.

Read article →
QFinch insight

Read coverage before counting findings

A useful security result tells you what was examined and what remains unknown.

Read article →
QFinch insight

Plan the response to an exposed secret

Source cleanup is one part of credential remediation.

Read article →

Explore practical perspectives on software supply-chain risk, assessment coverage and remediation planning.