MSManos Saratsisindromeas.hashnode.dev·1h ago · 6 min readWhat Is AI SAST? How Agentic Code Review Differs From Pattern-Matching Static AnalysisOriginally published on the Dromeas blog. In short: classic SAST matches known-bad patterns, fast and repeatably. AI SAST adds reasoning about data flow and intent across files, which catches behavior00
MSManos Saratsisindromeas.hashnode.dev·12h ago · 5 min readISO 42001 for Engineering Teams: What It Actually Asks You to ProveOriginally published on the Dromeas blog. In short: ISO 42001 is a voluntary, certifiable standard for managing AI systems. For engineering teams it's mostly about evidence: showing how AI-assisted ch00
MSManos Saratsisindromeas.hashnode.dev·Sep 17 · 8 min readBehavioral Bugs Are Still Slipping Through AI Code Review. Here's What Actually Catches Them.Originally published on the Dromeas blog. The pull request looks clean, the linter's green, the tests pass — and the code still does the wrong thing the moment someone hands it an input nobody thought00
MSManos Saratsisindromeas.hashnode.dev·Sep 13 · 8 min readShadow AI in Your Codebase: The Governance Gap Most CISOs Haven't Mapped YetYour AI code governance policy probably covers the tools you approved. It says nothing about the ones your developers are actually using. That gap has a name now, shadow AI, and in 2026 it's stopped b00
MSManos Saratsisindromeas.hashnode.dev·Sep 13 · 5 min readWhich AI Model Writes the Most Secure Code? What the 2026 Data Actually ShowsAsk five engineering leaders which AI coding model is "safe," and you'll get five confident, contradictory answers — most of them based on a vendor's marketing page rather than an actual security test00