Skip to main content

Ship to production safely. Security is already handled.

SmoothGlue runs every security scan automatically on every build. Your job is the app — the platform handles compliance.

Console role:OrgPrivileged·OrgUser
▶ Demo videos

Getting started


Security on every build

Pillars of Creation — zero-config security scanning
SBOM · SAST · Container scanning · Dependency scanning — automatic on every pipeline

Every app onboarded through the Console gets the full Pillars of Creation pipeline: Syft generates a CycloneDX SBOM, Semgrep runs SAST, Grype cross-references the SBOM against known CVEs, and OWASP ZAP tests the running app. None of this requires developer configuration. Builds with critical findings fail automatically — they never reach a namespace that could affect production.


How-to guides

Step-by-step operational guides for licensed customers.