
Application security platforms detect vulnerabilities in software artifacts. But when teams investigate risk, they must also understand how those artifacts were created. Connecting detection with development-origin context provides that missing perspective.
Modern application security workflows operate across two distinct surfaces:
1. Artifact detection — identifying vulnerabilities in code, dependencies, configuration, and build outputs.Most security platforms specialize in the first surface.
Investigation and remediation frequently require the second.
As software creation increasingly incorporates AI-assisted workflows alongside human development, the boundary between detection and origin becomes operationally significant.
Application security platforms evaluate artifacts:
These systems determine:
Detection establishes that risk exists.
It does not inherently record the conditions under which the change was introduced.
When a finding is surfaced, investigation typically requires reconstruction across:
This reconstruction process becomes more complex in hybrid human and AI-assisted development environments.
A single code change may involve:
Commit metadata does not always distinguish between these contributing elements.
During remediation, organizations often need to determine:
These are questions about origin, not artifact state.
Developer Security Posture Management (DevSPM) focuses on observable developer actions during software creation.
It associates code changes with the developers and AI-assisted workflows that produced them across source control and CI/CD systems.
When correlated with vulnerability findings, this produces development-origin context — attributable information identifying the identity and actions involved in how risk entered the codebase.
DevSPM does not replace artifact-focused security systems.
It introduces additional context at the creation layer that can be incorporated into existing investigation and governance workflows.
Archipelo and Checkmarx have partnered to correlate vulnerability findings with development-origin context within software delivery workflows.
Checkmarx provides application security testing and Application Security Posture Management (ASPM) to identify and manage software risk across development pipelines.
Archipelo provides creation-layer visibility through DevSPM.
Together, these systems allow organizations to analyze:
1. The presence of riskThis alignment connects artifact detection with attributable origin context inside existing security workflows.
Consider a vulnerability detected in a repository.
Traditional workflow:
With correlated origin context:
The difference lies in the availability of attributable creation evidence during remediation.
As development workflows incorporate AI-assisted tooling and automation, software creation becomes distributed across identities and systems.
Security analysis that relies solely on artifact inspection may not capture the conditions under which a change was introduced.
Incorporating creation-layer context allows investigation processes to reference recorded identity and action data in addition to artifact state.
Detection and origin serve distinct roles within the same workflow.
Detection determines that a vulnerability exists.
Origin context identifies the conditions under which it was introduced.
Application security workflows incorporate both perspectives when investigation requires attributable evidence.
Archipelo establishes a foundational observability layer for developer-attributed actions and related SDLC events — forming the data foundation for security and governance controls.
Request a Demo