GitLab announced the general availability of GitLab Duo with Amazon Q.
Security Journey announced support for WCAG, SCIM and continued compliance with SOC2 Type 2, which are leading industry standards.
The new capabilities mean large enterprises can now provide application security education to their development teams from a platform that meets security, global accessibility, and automated user provisioning requirements. These features ensure that in-depth training programs are provided to all learners including those who are sight and hearing-impaired, streamline user access and lifecycle management, and provide additional assurances on the rigorous security of the platform itself.
Specifically, the Security Journey platform now supports:
Web Content Accessibility Guidelines (WCAG), Section 508 (US) and EN 301 549 (EU)*
- These accessibility standards/guidelines focus on ensuring web content such as text, images, sounds, code or markup that defines structure and presentation can be understood by people with disabilities.
- Security Journey lessons now provide captions and “alt text” for images so that learners can see and hear content using assistive technologies.
- Learner interface and over 800 lessons have accessibility features.
- This is an industry first for an application security training provider.
System for Cross-Domain Identity Management (SCIM)
- SCIM is an open standard for automating user provisioning across domains, reducing the time and complexity typically associated with the process.
- It removes the need for manual user management and minimizes human error, meaning program admins can spend more time with learners.
System and Organization Controls (SOC) 2 Type 2
- SOC 2 is an international standard designed to help service organizations provide assurance about their security, availability, processing integrity, confidentiality, and privacy controls.
- Security Journey customers can be confident that their sensitive data will be handled in line with industry best practices.
*The technical requirements of the Section 508 procurement law in the US refer to WCAG for web content, documents and software. Similarly, EN 301 549 is the technical standard that allows the European Commission to enforce policies across Europe.
Security Journey CEO, Joe Ferrara, said, “I believe this marks a new maturity level in the market – making it appealing for large enterprises to move from less effective home-grown training to an in-depth progressive program built by AppSec experts.”
Industry News
Perforce Software and Liquibase announced a strategic partnership to enhance secure and compliant database change management for DevOps teams.
Spacelift announced the launch of Saturnhead AI — an enterprise-grade AI assistant that slashes DevOps troubleshooting time by transforming complex infrastructure logs into clear, actionable explanations.
CodeSecure and FOSSA announced a strategic partnership and native product integration that enables organizations to eliminate security blindspots associated with both third party and open source code.
Bauplan, a Python-first serverless data platform that transforms complex infrastructure processes into a few lines of code over data lakes, announced its launch with $7.5 million in seed funding.
Perforce Software announced the launch of the Kafka Service Bundle, a new offering that provides enterprises with managed open source Apache Kafka at a fraction of the cost of traditional managed providers.
LambdaTest announced the launch of the HyperExecute MCP Server, an enhancement to its AI-native test orchestration platform, HyperExecute.
Cloudflare announced Workers VPC and Workers VPC Private Link, new solutions that enable developers to build secure, global cross-cloud applications on Cloudflare Workers.
Nutrient announced a significant expansion of its cloud-based services, as well as a series of updates to its SDK products, aimed at enhancing the developer experience by allowing developers to build, scale, and innovate with less friction.
Check Point® Software Technologies Ltd.(link is external) announced that its Infinity Platform has been named the top-ranked AI-powered cyber security platform in the 2025 Miercom Assessment.
Orca Security announced the Orca Bitbucket App, a cloud-native seamless integration for scanning Bitbucket Repositories.
The Live API for Gemini models is now in Preview, enabling developers to start building and testing more robust, scalable applications with significantly higher rate limits.
Backslash Security(link is external) announced significant adoption of the Backslash App Graph, the industry’s first dynamic digital twin for application code.
SmartBear launched API Hub for Test, a new capability within the company’s API Hub, powered by Swagger.
Akamai Technologies introduced App & API Protector Hybrid.