Security testing glossary

Plain-language definitions of application, API, cloud, and AI/MCP security testing terms, written by practitioners who run scoped, non-disruptive assessments for B2B SaaS teams.

Use this glossary as a reference when evaluating security testing approaches.

Browse glossary topics by category

Group terms by the kind of testing or system surface you are exploring.

AI and LLM security

Coverage for model behavior, tool access, and prompt-driven risks.

Application and API testing

Definitions focused on application logic, data paths, and API abuse.

Cloud and infrastructure testing

Terms that cover identity, configuration, and workload protection.

Safe next step

Have a question about a term or how it applies?

Share what you are building and the terminology that is unclear. We will point you to the right glossary entries, explain how we test, and outline scope only if you want it.

Ask a question

or read the first pentest guide first

No commitment required
Plain-language answers
You decide the pace