BlueprintPage 50
50PLATFORM SECURITY
Secure SDLC & Product Security
The product’s own security program is part of the customer buying decision.
- Priority
- P0
- Phase
- Foundation
- Primary owner
- CISO / Engineering
- Status
- Blueprint
Objective
Customers will evaluate Agent Trust Cloud as critical security infrastructure. Product security must therefore be a company capability, not a checklist added before enterprise sales. Build controls into development, release and operations from the first production version.
What to build
- Threat modeling for gateway, policy, identity, connectors, admin and evidence paths.
- SAST, dependency/SBOM, secrets scanning and infrastructure-as-code scanning in CI.
- DAST/API security testing and regular penetration tests.
- Protected branches, reviewed production changes and signed builds where feasible.
- Vulnerability intake, severity SLAs and coordinated disclosure policy.
Implementation decisions
- Maintain separate dev/test/prod accounts and secrets.
- Create security regression tests for tenant isolation and policy bypass.
- Log privileged production access and use just-in-time elevation.
- Prepare SOC 2 readiness practices as enterprise traction develops.
Definition of done
- No production release bypasses required security gates.
- Critical vulnerabilities have documented remediation SLA and owner.
- Security incidents trigger postmortem and control update.
Success metrics
- Critical findings open
- Patch SLA compliance
- Security tests per release
- Privileged production sessions
TRUST SALES
The product’s own security program is part of the customer buying decision.