Skip to content
  1. Payment Platform
  2. Report

Payment Platform

DevSecOps security coverage assessment · September 14, 2026

Choose and order sections

In this report

  1. What is in place today
  2. The three numbers
  3. Where the gaps are

Left out

  • What was assessed
  • Across the lifecycle
  • Coverage by capability
  • Against the frameworks
  • Recommended next improvements
  • How these numbers were produced

Choosing and ordering sections is part of the free assessment. The shape travels in the address, so it survives a reload and can be bookmarked; nothing is stored. A link to your own report still needs your session — a report link somebody else can open is not built yet.

1What is in place today

Every control this assessment recorded as being in place — the Ist side of the coverage number, named rather than counted.

What is in placeToolHow it runsEnforcementWeight carriedEffectivenessMaturity
Trivy dependency scan on pull requests and in CITrivyautomateda warning3675%2
Trivy gate on the container buildTrivyautomateda warning2775%2
Argo CD reconciliation against GitArgo CDcontinuousa warning2450%2
Checkov Terraform scan on pull requests and in CICheckovautomateda warning1259%2
Entra Workload Identity on AKSno toolautomatednot enforced1225%2
Trivy image scan in CI and registryTrivyautomatedblocking1294%4
Defender for Cloud vulnerability assessment in productionMicrosoft Defender for Cloudcontinuousa warning1073%2
Renovate dependency update pull requestsRenovateautomatednot enforced925%2
Semgrep rules on pull requestsSemgrepautomateda warning967%2
SonarQube pull request gateSonarQubeautomatedblocking994%4
Annual third-party penetration testno toolmanualnot enforced60%1
Default-deny NetworkPolicies in the clusterno toolautomatedblocking663%2
DefectDojo as the finding destinationDefectDojoautomatedinformational650%2
SonarQube analysis of the main branchSonarQubeautomateda warning675%2
Azure Key Vault for application secretsno toolautomatednot enforced325%2
Azure Policy deny assignments on resource deploymentsno toolautomatedblocking363%2
DefectDojo SLA policy per severityDefectDojoautomatedinformational357%2
Kyverno policies in audit modeKyvernocontinuousinformational340%2
Azure Monitor log pipelineno toolcontinuousinformational240%2
Gitleaks over the repository and its historyGitleaksautomatedblocking294%4
Architecture board sign-off on major changesno toolmanualapproval-required129%1
Branch protection requiring a second reviewerGitHub Advanced Securitysemi-automatedapproval-required141%1
CODEOWNERS review on the payment pathsGitHub Advanced Securitysemi-automatedapproval-required141%1
Defender for Cloud posture on the production subscriptionMicrosoft Defender for Cloudcontinuousa warning173%2
Incident response runbook, rehearsed twice a yearno toolmanualnot enforced10%1
OWASP ZAP baseline scan against TESTOWASP ZAPsemi-automatedinformational145%1
STRIDE workshop held at design timeno toolmanualnot enforced10%1

Weight, not a count: a scope carries the weight of the requirement level behind it, and the coverage percentage is over those same weights. A control carrying zero weight is in place but covers nothing this profile requires.

2The three numbers

Coverage

47%

Effectiveness

61%

Maturity

1.0 / 5 (Available)

198 covered221 not covered

Coverage
198 of 419 weighted scopes are covered by something. 250 scopes were required in total.
Effectiveness
How much those controls actually do. 35% of this score could not be assessed, because evidence collection and ownership are not part of this release; those components were excluded rather than guessed.
Maturity
Averaged over everything the profile requires, with uncovered scope counting as level 0. Coverage and maturity move independently: a control can run everywhere and still be an immature process.

3Where the gaps are

170 gaps in total, 95 of them critical or high.

SeverityControlWhereWhat is wrong
criticalAuthenticated Dynamic ScanProduction · CI Pipelinenothing covers it
criticalPeriodic Penetration TestProduction · Manual Reviewexpected runs automatically, actual run by hand
criticalPeriodic Penetration TestProduction · Manual Reviewexpected runs automatically, actual run by hand
criticalVulnerable Dependency GateProduction · Java · CI Pipelineexpected blocking, actual a warning
criticalVulnerable Dependency GateProduction · Java · Release Gatenothing covers it
criticalVulnerable Dependency GateProduction · Spring Boot · CI Pipelineexpected blocking, actual a warning
criticalVulnerable Dependency GateProduction · Spring Boot · Release Gatenothing covers it
criticalVulnerable Dependency GateProduction · React · CI Pipelineexpected blocking, actual a warning
criticalVulnerable Dependency GateProduction · React · Release Gatenothing covers it
criticalAdmission Policy EnforcementProduction · Kubernetes · Admissionnothing covers it
criticalIaC Misconfiguration DetectionProduction · Helm · Pull Requestit runs elsewhere, but not for this technology
criticalIaC Misconfiguration DetectionProduction · Helm · CI Pipelineit runs elsewhere, but not for this technology
criticalInfrastructure Drift DetectionProduction · Terraform · Continuous Scanit runs elsewhere, but not for this technology
criticalInfrastructure Drift DetectionProduction · Terraform · Runtimeit runs elsewhere, but not for this technology
criticalInfrastructure Drift DetectionProduction · Azure · Continuous Scanit runs elsewhere, but not for this technology

The remaining 80 critical or high gaps are in the CSV export.