Web Security

Runtime security guides

Enforcing security decisions while the application runs, in the path of the action, with application context.

What these guides cover

Runtime security enforces policy while an application is executing, at the moment untrusted input reaches code or an action is about to take effect. It is distinct from pre-deployment scanning, which never sees live input, and from monitoring, which reports after the fact. The defining property is that a decision arrives before the effect: the application receives an allow, block, redact, or limit result and branches on it. Effective runtime controls need both speed and context, because a decision in the request path must be fast enough to keep, and a decision worth making requires knowing the user, the route, the target object, and the operation. Controls must also define explicit behavior when a security dependency is slow or unavailable, per action rather than globally.

Risks

  • Attacks arriving in live traffic that pre-deployment testing cannot see
  • Authorization decisions made without user or object context
  • Consequential actions on paths that never cross the network perimeter
  • Controls that fail open silently or fail closed indiscriminately

Control priorities

  • Enforcement in application code, in the path of the action
  • Decisions using authenticated identity, route, object, and tenant
  • Coverage of tool calls, queue consumers, and background jobs
  • Dry-run measurement and per-action failure behavior

Recommended reading order

Start with runtime application security for the definition, lifecycle position, and comparison against network and gateway controls. Use pre-runtime vs post-runtime tooling to separate detection from enforcement when evaluating vendors, then read the LLM runtime security guide for AI-specific failure modes and the local inspection guide for data residency.

Guides in this collection

Runtime security

What Is Runtime Application Security?

Runtime application security enforces controls in the path of the action, using the application's own context.

Read guide
Runtime security

How to add app security in a few lines of code

Install an SDK, configure rules once, and call it at the top of each handler – no proxy and no DNS change.

Read guide
Runtime security

SDK-based security vs WAF vs API gateway

What each layer sees, and why teams add bots, rate limits, and attack blocking in application code instead of only at the edge.

Read guide
Runtime security

Application runtime security vs container runtime security

Container runtime security watches syscalls. Application runtime security decides whether a request or tool call may proceed.

Read guide
Runtime security

Developer-first Cloudflare alternatives for application security

Need bot protection and rate limits without moving DNS? Compare application-layer alternatives to Cloudflare, not other CDNs.

Read guide
Runtime security

Best Application Security Tools for Developers (2026)

SDK, WAF, or scanner? Compare where each application security tool runs, what it can see, and what it costs an indie developer or startup.

Read guide
Runtime security

How do I detect and block attacks at runtime?

Detect injection, abuse, exfiltration, and agent manipulation in the handler, then deny before the query, the charge, or the model.

Read guide
Runtime security

Does Next.js need a WAF?

Does Next.js need a WAF? Yes, for scanners, known CVEs, and PCI DSS 4.0. Prefer an in-app Shield rule you can dry-run behind.

Read guide
Runtime security

What is permissions-based security in Next.js?

Authentication names the user, Permit.io decides whether that identity may act on an object, and Arcjet stops attacks and abuse on the request.

Read guide