Skip to content
Scale To Zero by Cloudanix
NT

Guest

Neelu Tripathy

Senior Security Architect, Adobe

Neelu Tripathy is a Senior Security Architect at Adobe and hosts the Breakpoint Security podcast. She has close to two decades of experience in security, securing systems and organizations.

Episode with Neelu

Questions Neelu answered

  • What security controls are non-negotiable when building products for AI-powered workplaces?

    Start with the fundamentals, because AI-generated code is built on the same patterns humans have written for years. Neelu lists authentication that can identify every entity making changes (users, machines and agents), data security, auditing, hardened configurations, and logging and monitoring beyond application telemetry. AI-specific controls are added on top of these.

  • What product security gaps do architecture reviews commonly find?

    User authentication is usually covered, because developers treat it as functionality; the gaps are elsewhere. Neelu points to build systems, development environments and promotion between environments (the supply chain), encryption and network segregation of data stores, observability, and throttling for spikes in access. Supporting systems such as message brokers and caches can be attacked too, so check whether services authenticate to each other and whether their tokens are short-lived.

  • Where should you start when prioritising security in the SDLC?

    Neelu's practical answer is to secure the build systems and build infrastructure first, before the code itself. Then make sure security and compliance requirements reach the backlog, security is automated in the pipeline, and designs are reviewed. In agile teams, stay release-focused (secure a feature like checkout before it ships) and iterate on security with every release.

  • Why do security tools fail to stop breaches?

    Neelu sees no direct correlation between owning tools and avoiding breaches. Tools in blocking mode can overwhelm developers with thousands of findings, many of them false positives, unreachable or not exploitable, so issues stay unfixed; other breaches come from zero days or new changes that pull in libraries. Her answer is to focus on controls rather than detection tools, and to build fixes into the system through automation.

  • How do you keep product security from slowing down engineering velocity?

    Treat velocity as the North Star, since time is currency for fast-moving and agentic teams. First, decide what security systems you can provide, built or bought; second, embed security requirements into concentrated places of engineering power such as pipelines, artifactories, registries and shared storage to reach the most developers. Third, package security so it is easy to consume, like a golden image or an automated upgrade PR from Dependabot or Renovate that developers only need to review and accept.

  • What security controls does agentic development need?

    Beyond the fundamentals, Neelu points to a vetted registry for AI tools and MCP servers, which she treats like dependencies, and to identifying and registering agents so their actions can be traced. She also calls out controls on agent-to-agent and LLM gateway traffic, sandboxed, isolated and ephemeral agent runtimes, and security for context: how it is stored, traced and linked, and what data access it grants an agent.

New episodes twice a month

No security question left unanswered.

Follow Scale To Zero wherever you listen, or send us the question your team is stuck on and we will put it to an expert.