Security testing glossary
Plain-language definitions of application, API, cloud, and AI/MCP security testing terms, written by practitioners who run scoped, non-disruptive assessments for B2B SaaS teams.
Use this glossary as a reference when evaluating security testing approaches.
Alphabetical index of security testing terms
Each entry is a concise definition with context on how the term shows up in real security testing, plus links to related concepts for quick cross-reference.
Terms starting with A
Terms starting with B
Terms starting with C
Terms starting with I
Terms starting with K
Terms starting with L
Terms starting with M
Browse glossary topics by category
Group terms by the kind of testing or system surface you are exploring.
AI and LLM security
Coverage for model behavior, tool access, and prompt-driven risks.
Application and API testing
Definitions focused on application logic, data paths, and API abuse.
Cloud and infrastructure testing
Terms that cover identity, configuration, and workload protection.
Safe next step
Have a question about a term or how it applies?
Share what you are building and the terminology that is unclear. We will point you to the right glossary entries, explain how we test, and outline scope only if you want it.
Ask a questionor read the first pentest guide first