Skip to content
Scale To Zero by Cloudanix

Topic

Application Security

Product security and AppSec in practice: threat modeling, secure SDLC, developer-friendly guardrails and closing the gaps tools leave behind.

20 episodes · 6 questions answered

Application Security: questions answered

What security controls are non-negotiable when building products for AI-powered workplaces?

Start with the fundamentals, because AI-generated code is built on the same patterns humans have written for years. Neelu lists authentication that can identify every entity making changes (users, machines and agents), data security, auditing, hardened configurations, and logging and monitoring beyond application telemetry. AI-specific controls are added on top of these.

Neelu Tripathy · Adobe

What product security gaps do architecture reviews commonly find?

User authentication is usually covered, because developers treat it as functionality; the gaps are elsewhere. Neelu points to build systems, development environments and promotion between environments (the supply chain), encryption and network segregation of data stores, observability, and throttling for spikes in access. Supporting systems such as message brokers and caches can be attacked too, so check whether services authenticate to each other and whether their tokens are short-lived.

Neelu Tripathy · Adobe

Where should you start when prioritising security in the SDLC?

Neelu's practical answer is to secure the build systems and build infrastructure first, before the code itself. Then make sure security and compliance requirements reach the backlog, security is automated in the pipeline, and designs are reviewed. In agile teams, stay release-focused (secure a feature like checkout before it ships) and iterate on security with every release.

Neelu Tripathy · Adobe

Why do security tools fail to stop breaches?

Neelu sees no direct correlation between owning tools and avoiding breaches. Tools in blocking mode can overwhelm developers with thousands of findings, many of them false positives, unreachable or not exploitable, so issues stay unfixed; other breaches come from zero days or new changes that pull in libraries. Her answer is to focus on controls rather than detection tools, and to build fixes into the system through automation.

Neelu Tripathy · Adobe

How do you keep product security from slowing down engineering velocity?

Treat velocity as the North Star, since time is currency for fast-moving and agentic teams. First, decide what security systems you can provide, built or bought; second, embed security requirements into concentrated places of engineering power such as pipelines, artifactories, registries and shared storage to reach the most developers. Third, package security so it is easy to consume, like a golden image or an automated upgrade PR from Dependabot or Renovate that developers only need to review and accept.

Neelu Tripathy · Adobe

What security controls does agentic development need?

Beyond the fundamentals, Neelu points to a vetted registry for AI tools and MCP servers, which she treats like dependencies, and to identifying and registering agents so their actions can be traced. She also calls out controls on agent-to-agent and LLM gateway traffic, sandboxed, isolated and ephemeral agent runtimes, and security for context: how it is stored, traced and linked, and what data access it grants an agent.

Neelu Tripathy · Adobe

Episodes

New episodes twice a month

No security question left unanswered.

Follow Scale To Zero wherever you listen, or send us the question your team is stuck on and we will put it to an expert.