Layer 05 · Engineer · Project or subscription

Secure SDLC & Secure AI-DLC

STP builds security into the development lifecycle: static and dynamic application security testing, dependency and supply-chain controls, secrets management and policy-as-code: and extends the same discipline to the AI development lifecycle, covering model supply chain, prompt injection defence and AI data governance.

Secure SDLC & Secure AI-DLC

Security findings are cheapest to fix while the developer still has the code in their head. Once a release is in production, the same finding costs an incident, a change window and a retest. Secure SDLC is mostly about moving the feedback earlier.

We integrate static analysis, dynamic testing and dependency scanning into the pipeline with thresholds your team can actually live with: because a gate that fires constantly gets disabled within a fortnight, and then you have neither security nor velocity.

The newer problem is AI. Teams are shipping features built on models, with prompts as untrusted input paths, third-party model weights as unaudited dependencies, and company data flowing into inference endpoints nobody reviewed. Secure AI-DLC applies the same lifecycle discipline: what is the model supply chain, where is untrusted input handled, what data leaves the boundary, and how is any of it tested.

Very few providers anywhere have practical answers here yet. We are building this capability deliberately, and we would rather describe honestly what we can do today than oversell it.

What is included

  • Static application security testing (SAST) in the pipeline
  • Dynamic application security testing (DAST)
  • Software composition analysis and dependency scanning
  • SBOM generation and supply-chain provenance
  • Secrets scanning and secrets management
  • Container and image scanning
  • Policy-as-code and automated guardrails
  • Threat modelling workshops with development teams
  • Secure coding guidance and developer enablement
  • Secure AI-DLC: model supply chain review and governance
  • Prompt injection and untrusted input defence for AI features
  • AI data governance: what leaves the boundary, and under what control
  • Penetration testing (STP retains penetration testing capability in-house)

What you get out of it

  • Findings raised while the code is still being written
  • A dependency inventory you can answer questions about
  • AI features shipped with a reviewed data and model boundary

Questions

What is the difference between SAST and DAST?
SAST analyses source code without running it, catching issues like injection-prone patterns and unsafe API use early, at the cost of false positives. DAST tests the running application from the outside, finding issues that only appear at runtime (configuration, authentication and session handling) but only in code paths it reaches. They find different classes of problem and a mature pipeline uses both.
What is Secure AI-DLC?
Applying secure development lifecycle discipline to systems built on AI models. In practice it covers the model supply chain (where weights came from and whether they are trusted), treating prompts and retrieved content as untrusted input, controlling what data crosses the inference boundary, access control over model endpoints, and testing for prompt injection and data leakage. It is an emerging discipline and we describe our capability in it honestly rather than as a finished product.

Secure SDLC & Secure AI-DLC

A live engineer calls you back within 1 hour.

Start a conversation