Legit has launched Legit context, an application security posture management (ASPM) platform that aims to enhance program maturity by integrating various data points. This new tool is designed to help organizations assess and mitigate the most pressing application vulnerabilities that present business risks.

Legit context delivers insights into both applications and their development environments, enabling chief information security officers (CISOs) and their teams to locate, address, and prevent significant vulnerabilities. This release follows a prior announcement in January 2025 concerning root cause remediation that allows customers to tackle multiple AppSec issues with a single solution.

Liav Caspi, co-founder and CTO of Legit Security, stated, “Organizations are challenged by an overwhelming number of vulnerabilities and very little actionable data on their actual exploitability and impact. The reality is that simple risk scoring or relying on CVSS scores alone only goes so far...Our new ASPM capabilities, assisted by AI, provide the context, visualization, and actionable data.”

Legit context offers a holistic view of vulnerabilities by establishing an application catalog that encompasses key factors such as sensitive data usage, Internet exposure, and compliance risks. This allows security and development teams to prioritize their remediation efforts effectively.

Key features of Legit context include:

  • Auto context detection: Analyzing the context of an application to assess business impact.
  • Deep code-to-cloud scanning: Integrating disparate data points to deliver a comprehensive view of vulnerability risks.
  • Application bill-of-materials: Mapping all components that contribute to security risk management.
  • Vulnerability risk scoring: Customizing workflows based on the business impact of vulnerabilities.

Legit also introduced capabilities for application API discovery, allowing organizations to manage all APIs and monitor for changes that could introduce risks.

These new features are intended to facilitate a better understanding of application risk and enhance DevSecOps processes for future prevention.