Launch
Security foundations for startups and single-product teams
For startups and single product teams getting security right from day one.
What's included
- NIST SSDF-aligned secure SDLC baseline and pilot rollout
- Light architecture review and threat modeling for priority systems
- Basic secure code review process and developer training
- Introductory DevSecOps and CI/CD security setup
- Basic AI coding policy guidance
- Executive summary reporting and optional maturity snapshot
Included services
Implement secure software development lifecycle practices
View serviceComprehensive security training for development teams
View serviceEstablish secure code review processes and practices for development teams
View serviceThreat modeling and abuse case analysis for secure design
View serviceComprehensive security architecture review and recommendations
View servicePackage comparison
| Capability | Launch | Scale | Enterprise |
|---|---|---|---|
| Secure SDLC baseline | Included | Included | Enterprise-wide |
| Architecture review | Light | Priority systems | Architecture board support |
| Threat modeling | Light | Product-level | Program-level |
| Secure code review process | Basic | Full workflow | Enterprise standard |
| Developer security enablement | Basic | Role-based | Champions + continuous enablement |
| DevSecOps setup | Basic | Advanced | Enterprise standard |
| CI/CD pipeline security | Basic | Advanced | Enterprise policy |
| Software supply chain security | Basic | Included | Full governance |
| AI-assisted development security | Optional | Included | Advanced |
| AI coding policy | Basic | Included | Enterprise governance |
| Secure AI SDLC | Optional | Optional | Included |
| Security champions | Intro | Program design | Program operation |
| Secure Engineering as a Service | Optional | Retainer | Dedicated model |
| Reporting | Summary | Monthly dashboard | Executive dashboard |
| Maturity review | Optional | Quarterly | Quarterly + annual roadmap |
Good fit if you
- Pre-Series B startups shipping their first production product
- Single squad needing a pragmatic 90-day security uplift
- Teams with no dedicated AppSec function yet
Not included (consider upgrading)
- Org-wide DevSecOps automation and supply-chain program (see Scale)
- Secure AI SDLC and agentic controls (see Enterprise)
- Dedicated secure engineering retainer
Typical scope for Launch
Launch fits a single product team establishing secure engineering basics — typically one primary application, a modest repository set, and a small group of contributing developers.
Typical: 1–5 applications
Typical: 1–10 repositories
Typical: 5–25 developers
Typical: 1–5 CI/CD pipelines
Typical: Emerging or limited AI tool use
Typical: Setup-focused; optional light retainer
What affects pricing
We do not publish fixed prices. Your proposal depends on scope and complexity.
Number of developers, squads, and products in scope affects enablement depth and coaching cadence.
More repos and apps require broader toolchain integration and governance models.
Platform choice, number of pipelines, and release frequency drive DevSecOps and release security effort.
Use of AI coding tools and AI-powered products determines AI governance and secure AI SDLC depth.
Regulated industries and audit cycles increase reporting, evidence packs, and maturity program scope.
One-time setup vs ongoing retainer vs dedicated pod — each maps to a different commercial structure.
Contact us for a tailored proposal based on your engineering context.
Extend your package
Extend your Build Secure package with specialized services.