Application security

Aha! Builder

Applications you build with Aha! Builder include built-in security reviews and enterprise-grade infrastructure protections. Run security reviews to evaluate your application's code and dependencies, then export the results to demonstrate compliance with your organization's governance standards.

Click any of the following links to skip ahead:

Security reviews

Navigate to Operate → Documents → Security to access four on-demand reviews for your application:

  • Review for secure by design principles: Checks that security is built into your application's architecture

  • OWASP Top 10 review for design or coding issues: Checks for the top 10 critical web application security risks

  • Static code analysis for vulnerabilities: Performs an automated source code review to identify potential flaws

  • Dependency vulnerability scan: Checks third-party libraries and dependencies for known security weaknesses

Click Run review to generate results for a review you have not run before. After a review completes, click Repeat review on that same review to generate fresh results against your current code.

Run reviews at any time — before deployment, after making changes, or as part of a regular review cycle.

Each completed review lists its Review date, Status, and a View report link, so you can open any past result. When a review completes, Elle also links the report in the chat window.

To export the report, select more options ( ... ). Then select PNG image (.png) or PDF document (.pdf) in the Export menu.

Did your application fail a review or pass with a low score? Give the Report to Elle (the AI assistant) and ask for suggested improvements, then rerun the review.

Top

Review exceptions

Not every review finding calls for a code change. When a finding reflects accepted risk or a known limitation in your application, record an exception on the review so later reviews account for it.

  • Hover over the review, then click Add exception.

    • The button stays hidden until you hover, and sits to the left of Run review or Repeat review.

  • Describe the accepted risk, known limitation, or other context the review should weigh.

  • Click Save exception to store the context, or Save and rerun review to generate a new review that incorporates it immediately.

The exception belongs to that review on that application. It persists across later runs and appears on the review page, so the next person who reads the report sees why the finding stands.

Governance administrators control whether you can record exceptions through the Allow review exceptions governance rule, which covers both security and privacy reviews. The rule is on by default.

Top

Framework and encryption

Aha! Builder applications run on TypeScript. All applications run on Amazon Web Services (AWS), the same infrastructure that powers the rest of the Aha! suite.

Aha! encrypts data in transit using TLS 1.2 and 1.3 with Let's Encrypt certificates and at rest using AES-256 encryption.

Top

Authentication for end users

End users of your application do not need an Aha! account. You configure authentication for your application separately under Operate → Configuration → Authentication. You can choose from five built-in sign-in methods:

  • Password

  • Aha!

  • Google

  • GitHub

  • Microsoft

To let your users sign in with your organization's own identity provider, add a Custom SSO (SAML, JWT) provider alongside the built-in methods. Each provider you add appears by name as its own option on the sign-in page.

SAML and JWT single sign-on (SSO) require the Aha! Builder Scale plan.

Top

Feedback received!

Error submitting feedback, please try again later