Services · Add-on
Application Security
Covers SAST/SCA, dependency triage, security review of sensitive PRs, threat modeling, and penetration-test management.
- Replaces
- AppSec Engineer
- Where it sits
- Add-on to any tier
Scope
What we own.
Every line is work an engineer carries, reports on monthly, and hands over documented if the retainer ends.
- SAST / SCA tooling deployment and tuning
- Dependency and supply-chain vulnerability triage
- Cybersecurity review of PRs touching auth, data handling or payments
- Threat modelling for new features and services
- Secure SDLC guardrails and developer guidance
- Pen test scoping, coordination and remediation tracking
- Vulnerability disclosure programme management
Boundaries
What this does not cover.
Stated up front so the scope in your proposal matches what actually gets done.
- Deep secure code review is not included.
- This module owns code and dependency vulnerabilities. Cybersecurity Program owns infrastructure and endpoint vulnerabilities. See Cybersecurity Program.
Related
The rest of the retainer.
Modules combine. Most engagements run three or four together.
Talk through Application Security.
Bring the systems, the role this has to cover, and the deadline. We come back inside 48 hours with a written scope.
