Applications you build with Aha! Builder include built-in security reviews and enterprise-grade infrastructure protections. Run security reviews to evaluate your application's code and dependencies, then export the results to demonstrate compliance with your organization's governance standards.
Click any of the following links to skip ahead:
Security reviews
Navigate to Operate → Documents → Security to access four on-demand reviews for your application:
Review for secure by design principles: Checks that security is built into your application's architecture
OWASP Top 10 review for design or coding issues: Checks for the top 10 critical web application security risks
Static code analysis for vulnerabilities: Performs an automated source code review to identify potential flaws
Dependency vulnerability scan: Checks third-party libraries and dependencies for known security weaknesses
Click Run review to generate results for a review you have not run before. After a review completes, click Repeat review on that same review to generate fresh results against your current code.
Run reviews at any time — before deployment, after making changes, or as part of a regular review cycle.
Each completed review lists its Review date, Status, and a View report link, so you can open any past result. When a review completes, Elle also links the report in the chat window.
To export the report, select more options ( ... ). Then select PNG image (.png) or PDF document (.pdf) in the Export menu.
Did your application fail a review or pass with a low score? Give the Report to Elle (the AI assistant) and ask for suggested improvements, then rerun the review.
Review exceptions
Not every review finding calls for a code change. When a finding reflects accepted risk or a known limitation in your application, record an exception on the review so later reviews account for it.
-
Hover over the review, then click Add exception.
The button stays hidden until you hover, and sits to the left of Run review or Repeat review.
Describe the accepted risk, known limitation, or other context the review should weigh.
Click Save exception to store the context, or Save and rerun review to generate a new review that incorporates it immediately.
The exception belongs to that review on that application. It persists across later runs and appears on the review page, so the next person who reads the report sees why the finding stands.
Governance administrators control whether you can record exceptions through the Allow review exceptions governance rule, which covers both security and privacy reviews. The rule is on by default.
Framework and encryption
Aha! Builder applications run on TypeScript. All applications run on Amazon Web Services (AWS), the same infrastructure that powers the rest of the Aha! suite.
Aha! encrypts data in transit using TLS 1.2 and 1.3 with Let's Encrypt certificates and at rest using AES-256 encryption.
Authentication for end users
End users of your application do not need an Aha! account. You configure authentication for your application separately under Operate → Configuration → Authentication. You can choose from five built-in sign-in methods:
Password
Aha!
Google
GitHub
Microsoft
To let your users sign in with your organization's own identity provider, add a Custom SSO (SAML, JWT) provider alongside the built-in methods. Each provider you add appears by name as its own option on the sign-in page.