Security testing glossary
Plain-language definitions of application, API, cloud, and AI security testing terms, written by practitioners who run scoped, non-disruptive assessments for B2B SaaS teams.
Use this glossary as a reference when evaluating security testing approaches.
Alphabetical index of security testing terms
Each entry is a concise definition with context on how the term shows up in real security testing, plus links to related concepts for quick cross-reference.
Terms starting with A
Adversarial testing for AI-enabled product behavior, tools, retrieval, agents, and workflows.
Security risks in agent autonomy, tool access, memory, and privilege boundaries.
Testing APIs for authentication, authorization, data exposure, and abuse paths.
Terms starting with B
Terms starting with C
Terms starting with I
Terms starting with K
Terms starting with L
Terms starting with M
Browse glossary topics by category
Group terms by the kind of testing or system surface you are exploring.
AI and LLM security
Coverage for model behavior, tool access, and prompt-driven risks.
Application and API testing
Definitions focused on application logic, data paths, and API abuse.
Cloud and infrastructure testing
Terms that cover identity, configuration, and workload protection.
Safe next step
Have a question about a term or how it applies?
Share what you are building and the terminology that is unclear. We will point you to the right glossary entries, explain how we test, and outline scope only if you want it.
Ask a questionor read the first pentest guide first