DevSecOps

FINOS AI Fund and OSERA: Open Source AI Governance for FSI

FINOS AI Fund and OSERA: Open Source AI Governance for FSI

FINOS and the Linux Foundation have announced the AI Fund, Project OSERA, and FDC3 3.0, targeting AI governance, supply chain remediation, and cross-industry interoperability in financial services. ECI Research examines what these coordinated moves mean for ITDMs and developers inside regulated institutions. The initiatives signal a shift from firm-level AI policy to mutualized, open governance infrastructure.

FINOS AI Fund and OSERA: Open Source AI Governance for FSI Read More »

VDI Modernization: Patching Gaps and Security Risk in 2026

VDI Modernization: Patching Gaps and Security Risk in 2026

The 2026 State of VDI Survey from Recast, Nerdio, and VMblog finds virtual desktop infrastructure firmly in active modernization, not retirement. Only 34% of VDI administrators are confident patches are applied on time, while over half cite lifecycle management as a top operational burden. ECI Research analyst commentary examines what this means for IT security strategy and the vendor landscape.

VDI Modernization: Patching Gaps and Security Risk in 2026 Read More »

Minimus Opens Free Secure Container Image Catalog | ECI Research

Minimus Opens Free Secure Container Image Catalog | ECI Research

Minimus is opening its entire catalog of near-zero CVE container images for free, with no registration required. ECI Research examines why the move targets the growing asymmetry between AI-accelerated vulnerability discovery and slow remediation, and what it means for enterprise DevSecOps strategy. Signed SBOMs and an agent-ready CLI make this more than a freemium play.

Minimus Opens Free Secure Container Image Catalog | ECI Research Read More »

Cequence Platform 9.0: AI-Native API Security for the Agentic Era

Cequence Platform 9.0: AI-Native API Security for the Agentic Era

Cequence Security has launched Platform 9.0, an AI-native API security release featuring an open MCP server, a built-in AI Assistant, and 250-plus pre-built compliance rules mapped to 25 global frameworks. The release positions Cequence as a composable security capability for agentic enterprise workflows, arriving as AI code governance tops enterprise security investment priorities. ECI Research data shows the compliance and agentic integration gaps this release directly targets.

Cequence Platform 9.0: AI-Native API Security for the Agentic Era Read More »

Baz Planner Targets AI Code Governance at the Source

Baz Planner Targets AI Code Governance at the Source

Baz announced Baz Planner, a pre-code gateway that intercepts AI-generated code at the planning stage to eliminate vulnerabilities before they are written. The company also closed a $9M seed extension, bringing total funding to $17M. ECI Research identifies AI code governance as the top enterprise security investment priority heading into 2026.

Baz Planner Targets AI Code Governance at the Source Read More »

Modulate Launches AI Music Detection API for Platforms at Scale

Modulate Launches AI Music Detection API for Platforms at Scale

Modulate has launched an AI Music Detection API that identifies AI-generated vocals and instrumentals directly from audio, without relying on uploader disclosure. Built on a three-model ensemble architecture, the API is designed for streaming platforms, distributors, and rights organizations that need to manage synthetic music at scale. The launch arrives as the music industry confronts the same AI governance gap that enterprise security teams are already racing to close.

Modulate Launches AI Music Detection API for Platforms at Scale Read More »

AI Code Visibility Gap Widens as Production Use Hits 44.7%

AI Code Visibility Gap Widens as Production Use Hits 44.7%

Flux’s AI Code Generation Reality Check finds nearly half of organizations are running AI-generated code in production, while 35% can’t ship it confidently due to inadequate visibility. ECI Research examines the governance and tooling gaps this creates, and what engineering leaders should do next.

AI Code Visibility Gap Widens as Production Use Hits 44.7% Read More »

Arcova Tackles Data Center Development Delays With End-to-End Model

Arcova Tackles Data Center Development Delays With End-to-End Model

Arcova has announced an end-to-end data center development offering that consolidates site selection, engineering, compliance, and operations under one accountable team. The company claims an 18-month reduction in development timelines and elimination of $60–200M in transition costs generated by fragmented vendor coordination. ECI Research analyst coverage examines why the organizational model, not the technology, is the real bottleneck.

Arcova Tackles Data Center Development Delays With End-to-End Model Read More »

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance

The Eclipse Foundation and ORC Working Group have launched the ORC Learning Hub, a free modular training platform helping developers, maintainers, and security teams prepare for the EU’s Cyber Resilience Act. With the first CRA obligations taking effect in September 2026, the initiative addresses a critical gap in role-specific compliance education for open source software supply chains. ECI Research analysts assess what this means for ITDMs and engineering teams navigating the new regulatory landscape.

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance Read More »