AppSec generalist first, then a fractional lead and services for the rest.
- Home
- Resources
- Blueprints
Blueprints
Templates you can take home.
Canvases, checklists and starter sets from the line. Free, with no sign-up when they ship.
Templates
Threat-model canvasOne board for data flows, trust boundaries and threats.Soon
Security RACIWho owns what, station by station.Soon
Pentest scope templateScope from the threat model and recent changes.Soon
Bug bounty scope & rulesAssets, rules, safe harbour, rewards.Soon
Pipeline hardening checklistPinned actions, scoped tokens, runners, protected workflows.Soon
KPI starter set
Metrics leadership actually reads.
- Share of new features with a threat model
- Median time from finding to fix, by severity
- Pipelines with pinned actions and scoped tokens
- Builds signed with provenance
- Pentest findings turned into detections
Download soon.
Team org charts
Security teams from 1 to 50.
AppSec, SOC, offensive and a manager, with the CISO owning policy and risk.
Offensive, SOC, AppSec, CTI, managers and the CISO, each with its own KPIs.