Services · Add-on

Application Security

Covers SAST/SCA, dependency triage, security review of sensitive PRs, threat modeling, and penetration-test management.

Replaces
AppSec Engineer
Where it sits
Add-on to any tier

Scope

What we own.

Every line is work an engineer carries, reports on monthly, and hands over documented if the retainer ends.
  • SAST / SCA tooling deployment and tuning
  • Dependency and supply-chain vulnerability triage
  • Cybersecurity review of PRs touching auth, data handling or payments
  • Threat modelling for new features and services
  • Secure SDLC guardrails and developer guidance
  • Pen test scoping, coordination and remediation tracking
  • Vulnerability disclosure programme management

Boundaries

What this does not cover.

Stated up front so the scope in your proposal matches what actually gets done.
  • Deep secure code review is not included.
  • This module owns code and dependency vulnerabilities. Cybersecurity Program owns infrastructure and endpoint vulnerabilities. See Cybersecurity Program.

Talk through Application Security.

Bring the systems, the role this has to cover, and the deadline. We come back inside 48 hours with a written scope.