What Is Runtime Application Security?
Runtime application security enforces controls in the path of the action, using the application's own context.
Read guideWeb Security
Enforcing security decisions while the application runs, in the path of the action, with application context.
Runtime security enforces policy while an application is executing, at the moment untrusted input reaches code or an action is about to take effect. It is distinct from pre-deployment scanning, which never sees live input, and from monitoring, which reports after the fact. The defining property is that a decision arrives before the effect: the application receives an allow, block, redact, or limit result and branches on it. Effective runtime controls need both speed and context, because a decision in the request path must be fast enough to keep, and a decision worth making requires knowing the user, the route, the target object, and the operation. Controls must also define explicit behavior when a security dependency is slow or unavailable, per action rather than globally.
Start with runtime application security for the definition, lifecycle position, and comparison against network and gateway controls. Use pre-runtime vs post-runtime tooling to separate detection from enforcement when evaluating vendors, then read the LLM runtime security guide for AI-specific failure modes and the local inspection guide for data residency.
Runtime application security enforces controls in the path of the action, using the application's own context.
Read guideInstall an SDK, configure rules once, and call it at the top of each handler – no proxy and no DNS change.
Read guideWhat each layer sees, and why teams add bots, rate limits, and attack blocking in application code instead of only at the edge.
Read guideContainer runtime security watches syscalls. Application runtime security decides whether a request or tool call may proceed.
Read guideNeed bot protection and rate limits without moving DNS? Compare application-layer alternatives to Cloudflare, not other CDNs.
Read guideSDK, WAF, or scanner? Compare where each application security tool runs, what it can see, and what it costs an indie developer or startup.
Read guideThe rule ships with the feature and runs in the request path.
Read guideDetect injection, abuse, exfiltration, and agent manipulation in the handler, then deny before the query, the charge, or the model.
Read guideAre Next.js server actions a security risk?
Read guideWere you affected by the Next.js middleware bypasses?
Read guideSQL injection is untrusted input that becomes SQL syntax.
Read guideDoes Next.js need a WAF? Yes, for scanners, known CVEs, and PCI DSS 4.0. Prefer an in-app Shield rule you can dry-run behind.
Read guideAuthentication names the user, Permit.io decides whether that identity may act on an object, and Arcjet stops attacks and abuse on the request.
Read guide