Case Study: Paddle reclaims two days of AppSec work per week with Apiiro
Key results
The challenge
Paddle, a payments infrastructure provider, ran a small application security team whose existing tools surfaced vulnerabilities too late in the development lifecycle, leading to delayed code releases and internal friction. The team lacked insight into who owned what code, making it hard to collaborate with developers on fixes.
The solution
Paddle rolled out Apiiro in stages through a GitHub integration, building a complete inventory across its nearly 500 repositories covering technologies, open-source usage, exposed secrets, and sensitive data. Apiiro's policy-as-code engine automated developer guardrails and enforced security checks on every pull request, and Paddle added Apiiro's open-source (SCA) and software supply chain security modules.
“The unique value that Apiiro provides Paddle is as a force multiplier we can do more with less, we can meet the developers where they're comfortable, we can provide them the information that they need to fix or to mitigate issues in a single unified view.”
JHJonny HerdVP of Information Security & Enterprise Technology, Paddle
The results, in context
Apiiro reports it monitors 100+ pull requests per week for Paddle, blocking high-risk changes that need further assessment, and gives the application security team back two days' worth of work per week by surfacing only the relevant, risky code changes. These figures are quoted from Apiiro's Paddle case study and dated to that public source.