Modern development teams rapidly release software. But speed creates risk.

Developers rely on cloud repositories and dozens of third-party tools to ship software fast. But the majority of threats targeting developer environments are delivered over encrypted traffic.

 

With Zscaler Internet Access, security teams can control developer traffic without breaking apps, frustrating engineers, or blocking releases: automate TLS/SSL inspection for over 30 developer tools while sandboxing code and unknown or large files with instant AI-verdicts.

THE PROBLEM

Developer environments generate high-value traffic that often goes uninspected

Many organizations bypass SSL/TLS inspection of developer-generated traffic because implementing inspection can result in “broken” apps since they may not trust the default system certificate store or perform certificate pinning, leading to unexpected errors. 

 

 

But inspecting traffic in developer environments remains critical to enterprise security: Over 87% of threats are delivered over encrypted channels1 yet most development environments go uninspected because applying TLS/SSL inspection to developer tools breaks them.

 

1 Encrypted Attacks 2024 Report by Zscaler ThreatLabz

Female developer stares at monitor screen

THE SOLUTION

Inspect and manage developer environment traffic at scale with Zscaler Internet Access

Developer teams can release at high velocity without compromising security

TLS/SSL inspection across 30+ popular developer tools
Inspect encrypted developer traffic at scale

Automate TLS/SSL inspection across 30+ popular developer tools without workflow disruption. Policy-based controls apply inspection broadly while maintaining targeted exemptions where needed.

cloud sandboxing analyzes scripts, packages, and files from third-party repositories
Stop threats before they reach your codebase

AI-powered cloud sandboxing analyzes scripts, packages, and files from third-party repositories in real time to catch malware, backdoors, and hidden malicious code before it's embedded in your applications.  

integrates with existing MDM and endpoint management workflows to deploy certificates
Enable developers without creating blind spots

Zscaler integrates with MDM, endpoint management, and Zscaler Digital Experience (ZDX) to deploy certificates automatically to developer endpoints so they can keep working in their preferred tools yet stay secure.

developer app categories, risk scoring, and SaaS security reporting
Gain full visibility and granular policy control

Pre-defined developer app categories, risk scoring, and SaaS security reporting give security architects and cloud ops teams the data they need to distinguish sanctioned from shadow IT developer tooling.

USE CASES

Gain Visibility of Developer Apps
  • Leverage pre-generated report of all developer apps with associated Risk Score 

  • Find developer tools generating traffic easily with the ZIA SaaS Security Application Report

  • Identify dev tools failing client SSL/TLS handshake and create an inspection rule to inspect the traffic  

SaaS Security Report screenshot
ENLARGE
Protect Against Risky, "Shadow IT" Developer Apps
  • Quantify the risk and attributes of endpoint applications and know app name, code signing status, threat level, certificate status, app CVEs and more

  • Quickly define security policy with predefined app & URL categories 

  • Rapidly distinguish between sanctioned and unsanctioned apps with granular risk-based controls

Application Investigation screenshot
ENLARGE
Block Threats and Protect Data in Encrypted Traffic
  • Inspect and secure encrypted developer tool-generated traffic at scale

  • Create and fine-tune inspection policy for both unsanctioned and sanctioned developer tools

  • Automate certificate rollout to developers' host machines using mobile device management (MDM) solutions like InTune, JAMF, and SCCM

Quickly define security policy for sanctioned and unsanctioned developer apps
ENLARGE

Frequently Asked Questions

Over 86% of all threats are delivered over encrypted traffic: not inspecting traffic in developer environments increases risk and leaves your organization vulnerable. Moreover, development teams release often and rapidly so your organization remains competitive and gains market share—but that speed can also lead to an oversight that causes a security incident. In this context, inspecting traffic and new files before they are embedded in the developer’s code base is paramount to maintaining a strong, resilient security posture.

In the past integrating encrypted traffic inspection has proven problematic for development teams: their code does not reference the correct certificate store or they design their app to employ “certificate pinning,” a security technique that prevents man-in-the-middle (MITM) attacks and secures access to your organization’s applications. Unfortunately, both scenarios prevent traffic TLS/SSL inspection via proxy.

 

Zscaler now provides the means for your security or IT teams to empower developer teams with scalable, policy-based TLS/SSL inspection or, in the case of certificate-pinned apps, easily bypass inspection for this category of apps.

Outright blocking means your developers can’t directly introduce risk during development,  prior to releasing new code to production in your environment. That said, without other DLP policy they could inadvertently introduce third-party code into the overall code base, resulting in malicious code with a backdoor or other threat being introduced into a production app. 


From a productivity standpoint, blocking access to other developer resources puts your software engineers at a competitive disadvantage: with ZIA’s SSL/TLS inspection integrated with their workflows, they can still remain competitive while preventing threats from compromising your organization’s security.