Skip to content
BlueprintPage 50
50PLATFORM SECURITY

Secure SDLC & Product Security

The product’s own security program is part of the customer buying decision.

Priority
P0
Phase
Foundation
Primary owner
CISO / Engineering
Status
Blueprint

Objective

Customers will evaluate Agent Trust Cloud as critical security infrastructure. Product security must therefore be a company capability, not a checklist added before enterprise sales. Build controls into development, release and operations from the first production version.

What to build

  • Threat modeling for gateway, policy, identity, connectors, admin and evidence paths.
  • SAST, dependency/SBOM, secrets scanning and infrastructure-as-code scanning in CI.
  • DAST/API security testing and regular penetration tests.
  • Protected branches, reviewed production changes and signed builds where feasible.
  • Vulnerability intake, severity SLAs and coordinated disclosure policy.

Implementation decisions

  • Maintain separate dev/test/prod accounts and secrets.
  • Create security regression tests for tenant isolation and policy bypass.
  • Log privileged production access and use just-in-time elevation.
  • Prepare SOC 2 readiness practices as enterprise traction develops.

Definition of done

  • No production release bypasses required security gates.
  • Critical vulnerabilities have documented remediation SLA and owner.
  • Security incidents trigger postmortem and control update.

Success metrics

  • Critical findings open
  • Patch SLA compliance
  • Security tests per release
  • Privileged production sessions

TRUST SALES

The product’s own security program is part of the customer buying decision.