Definition

What is SAST?

SAST (static application security testing) is a white-box testing approach that examines application code for security flaws without running it. SAST tools parse source code, bytecode, or compiled binaries, build a model of how data flows through the application, and flag patterns that indicate vulnerabilities — for example, user input reaching a database query without sanitisation.

What SAST finds

  • Injection vulnerabilities (SQL injection, command injection, XSS) traced from source to sink
  • Hardcoded secrets and credentials
  • Insecure cryptographic usage and weak random number generation
  • Unsafe deserialisation and path traversal patterns

Because SAST sees the code itself, it can point to the exact file and line that needs fixing — something black-box techniques cannot do.

Limitations

SAST cannot see the deployed environment. It misses server misconfigurations, missing security headers, TLS weaknesses, and vulnerabilities in third-party services — and it typically produces more false positives than runtime testing, because it cannot always tell whether a flagged path is reachable in practice.

SAST vs DAST

SAST inspects code from the inside; DAST probes the running application from the outside. SAST fits early in the development pipeline (often in CI on every commit), while DAST and external attack surface management assess what is actually exposed in production. The approaches are complementary rather than competing.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.