DevSecOps

GitLab's Governed Software Factory: What It Means for DevSecOps

GitLab’s Governed Software Factory: What It Means for DevSecOps

GitLab announced a connected governed software factory spanning artifact management, dependency firewall, secrets management, and AI impact analytics. The move addresses fragmented pipeline governance and rising supply chain risk from agentic development. ECI Research data shows why platform integration velocity and FedRAMP friction are the real decision drivers.

GitLab’s Governed Software Factory: What It Means for DevSecOps Read More »

CData Connect AI: Solving Enterprise AI Data Connectivity

CData Connect AI: Solving Enterprise AI Data Connectivity

CData VP of AI Architecture Amit Naik argues that enterprise AI project failures are misdiagnosed as model problems when the real issue is poor data connectivity and context management. The company’s Connect AI managed MCP server targets this gap with scoped, policy-governed data access designed for regulated environments. ECI Research analysis examines what this means for ITDMs managing token budgets and developers navigating compliance overhead.

CData Connect AI: Solving Enterprise AI Data Connectivity Read More »

GitLab 19.4: Governed Agentic Automation at Scale

GitLab 19.4: Governed Agentic Automation at Scale

GitLab 19.4 introduces the /goal command, open weight AI models, and expanded MCP server tools to scale agentic automation across engineering organizations. The release reframes GitLab as a governance and orchestration platform, not just a DevSecOps toolchain. For regulated and public sector buyers, the unified permission model and cost attribution layer address compliance friction that has slowed AI adoption.

GitLab 19.4: Governed Agentic Automation at Scale Read More »

Cyera Acquires Oasis Security: Betting on Agentic AI Security

Cyera Acquires Oasis Security as a Bet on Agentic AI Security

Cyera has completed its acquisition of Oasis Security, rebranding the combined offering as Cyera Identity and positioning it as trust infrastructure for the agentic enterprise. The move bets that identity and data security must converge at the point where AI agents operate. ECI Research examines whether the thesis holds and what it means for regulated enterprise buyers.

Cyera Acquires Oasis Security as a Bet on Agentic AI Security Read More »

RapidFort + CrowdStrike: Closing the Container Vulnerability Gap

RapidFort + CrowdStrike: Closing the Container Vulnerability Gap

RapidFort’s new integration with CrowdStrike Falcon Cloud Security targets the gap between vulnerability detection and remediation in Kubernetes environments. By ingesting SBOM and CVE data from Falcon and automating container image hardening, the two vendors aim to close a loop that has historically required significant manual intervention. The integration has particular relevance for federal and defense organizations operating in air-gapped environments.

RapidFort + CrowdStrike: Closing the Container Vulnerability Gap Read More »

Gemini 3.7 Flash: Price Cut and Performance Gains Reshape AI Agent Economics

Gemini 3.7 Flash: Price Cut and Performance Gains Reshape AI Agent Economics

Google has launched Gemini 3.7 Flash, cutting per-token pricing by 50% while posting significant improvements in software engineering, web development, and agentic workflow benchmarks. The release, arriving just three weeks after Gemini 3.6 Flash, signals an accelerating competitive cadence at the AI inference layer. ECI Research data shows enterprise AI-assisted coding is scaling fast, making first-pass code accuracy and integration friction the metrics that matter most.

Gemini 3.7 Flash: Price Cut and Performance Gains Reshape AI Agent Economics Read More »

PDQ Expands Endpoint Vulnerability Management to macOS and Six Ticketing Platforms

PDQ Expands Endpoint Vulnerability Management to macOS and Six Ticketing Platforms

PDQ has extended its vulnerability management workflow to macOS devices and added ticketing integrations with Zendesk, ServiceNow, and Halo. Three new APIs allow teams to push endpoint, vulnerability, and deployment data into external systems programmatically. The release positions PDQ as a unified endpoint management and security data platform for mixed Windows and macOS environments.

PDQ Expands Endpoint Vulnerability Management to macOS and Six Ticketing Platforms Read More »

AI Content Governance: Why the Output Layer Is the Real Risk

Why the Output Layer Is the Real Risk in AI Content Governance

Enterprise AI governance has advanced on access logging and provenance tracking, but most programs still lack enforcement at the content output layer. Markup AI calls this “compliance theater.” ECI Research data shows nearly two-thirds of practitioners already see elevated risk from AI-assisted development, making the case for output-layer controls more urgent.

Why the Output Layer Is the Real Risk in AI Content Governance Read More »

IREN Acquires Mirantis: Completing the AI Cloud Stack

IREN Acquires Mirantis: Completing the AI Cloud Stack

IREN has completed its acquisition of Mirantis, adding the k0rdent AI orchestration platform to its owned data centers and compute infrastructure. The deal represents a deliberate vertical integration play targeting enterprise AI Cloud buyers. ECI Research data shows AI-enabled development tools are the top investment priority for enterprises in 2026, validating the market IREN is now positioned to serve.

IREN Acquires Mirantis: Completing the AI Cloud Stack Read More »

Digital Media Provenance: Why C2PA Matters Beyond AI Fakes

Why C2PA Matters Beyond AI Fakes

A Utah judge’s rejection of unverified surveillance footage exposed a structural gap in digital media provenance that predates AI by decades. DigiCert is advancing C2PA, an open standard that cryptographically signs every edit in a media file’s history. ECI Research analysis explains why this matters for ITDMs and developers building media pipelines.

Why C2PA Matters Beyond AI Fakes Read More »