Blog

DevSPM: Unifying Vulnerability Detection and Creation-Origin Context in Software Security

Application security platforms detect vulnerabilities in software artifacts. But when teams investigate risk, they must also understand how those artifacts were created. Connecting detection with development-origin context provides that missing perspective.

Matthew Wise · Mar 4, 2026

Latest Blogs

Why Moltbot Demonstrates Security Must Move Upstream—From Code to Actors

Matthew Wise · Feb 5, 2026

The OWASP Agentic Top 10 Risks and the Emergence of Developer Security Posture Management (DevSPM)

Matthew Wise · Jan 13, 2026

The Missing Control Plane in AI-Native Software Security

Matthew Wise · Jan 7, 2026

Vibe Coding Without Vibe Collapse: Why AI-Augmented Software Development Needs a DevSPM Control Plane

Matthew Wise · Dec 9, 2025

AI Security Has Two Perimeters: The Model and the Coder

Matthew Wise · Nov 18, 2025

Shai-Hulud: One Worm Targeted One Coder and Put Billions at Risk—the Case for Developer Security Posture Management

Matthew Wise · Sep 23, 2025

One Phished Developer. Two Billion Downloads. The Blind Spot That Broke Software Security.

Matthew Wise · Sep 9, 2025

DevSPM and the Layer Zero Blind Spot

Paul Calatayud · Jul 15, 2025

The Next Control Point in Cybersecurity: From Artifact to Actor

Matthew Wise · Jul 2, 2025

The Shift Security Missed: Why Developers Are the Fifth Pillar of Software Security

Kacper Skawinski · Jun 24, 2025

Why AI Pipelines Are Forcing a Rethink of Security and Developer Identity

Paul Calatayud · Jun 17, 2025

Why Securing Developers—Not Just Code—Is the Future of Cybersecurity

Matthew Wise · Jun 4, 2025

Archipelo DevSPM: Redefining Enterprise Security at the Source of Innovation

Paul Calatayud · Mar 18, 2025

Archipelo’s DevSPM: Securing AI Coding’s Next Frontier—From Vibe Coding to Secure Innovation

Matthew Wise · Mar 17, 2025

From AI Code Discovery to a New Cybersecurity Imperative: Developer Security Posture Management (DevSPM)

Matthew Wise · Mar 5, 2025

Get Started

Archipelo establishes a foundational observability layer for developer-attributed actions and related SDLC events — forming the data foundation for security and governance controls.

Request a Demo