Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

USE CASE · SECURITY BY DESIGN

Security that ships with the project, not after it.

Every initiative, a project, an RFP, a new application, gets a security path proportionate to its risk: a fast lane for the routine, expert review for the critical, and nothing sitting in a queue.

Security-by-Design record Illustrative data

SBD-2026-00112

HR analytics data lake

Medium Application Internal only

analyticsdata-lakeGDPRHRTier 3 · Standard

  1. Contextualization
  2. Routing
  3. GRC analysis
  4. Action plan
  5. Monitoring
  6. Completed

Current step · Contextualization 50%

  • Business context
  • Documents
  • Suppliers Optional
  • Value chain Optional
  • Assessments Optional

Step incomplete

To continue: 1 document required, 0 provided.

The routing step reads this context and picks the path: fast lane for the routine, expert review for the critical. The step advances on evidence, not on a click.

THE SITUATION

The security gate everyone routes around.

  1. Security review is the bottleneck

    When the gate takes weeks, the business learns to go around it. Shadow projects are born compliant with nothing.

  2. Findings arrive after decisions

    The architecture is chosen, the vendor signed, the data model set. Then security speaks. Every finding is now a renegotiation.

  3. Exceptions live in inboxes

    Somebody accepted that risk in an email three years ago. Nobody remembers who, why, or until when.

  4. One process for everything

    A marketing microsite and a core-system migration go through the same forms. Too heavy for one, too light for the other.

CAPABILITIES

Proportionate security, built into the flow of work.

  1. Every initiative registered

    Projects, RFPs, applications, processes, infrastructure: one intake for everything the business starts, so nothing reaches production unseen.

  2. A process you design

    A visual builder assembles your Security by Design workflow from blocks: context, documents, suppliers, assessments, analysis, data privacy. Your process, not a vendor’s.

  3. Routing proportionate to risk

    Criticality and exposure decide the path: an AI-assisted fast track for standard initiatives, analyst-led review for the critical ones. Humans stay in the loop on both.

  4. Business language in

    Project owners answer a contextualization wizard in plain words: what it does, what data it touches, who is exposed. No security jargon required to enter.

  5. Controls from day one

    Each initiative receives its baseline controls, classification and privacy scoping before build, with recommendations tracked as actions, not emails.

  6. Exceptions with an expiry date

    When a requirement cannot be met, a formal derogation is filed: justified, approved at the right level, compensated by mitigations tracked as tickets, and time-bound.

PROPORTIONALITY

Not every project deserves a committee. Every project deserves a decision.

The projects that clog security governance are rarely the risky ones: they are the routine ones stuck in the same pipe. Route the routine through an assisted fast lane, and give your analysts their hours back for the initiatives that can actually hurt.

  1. 01

    Declare

    The project owner describes the initiative in business terms, in minutes. That declaration is the entry ticket.

  2. 02

    Route by risk

    Criticality and exposure route the initiative: fast lane or expert review. Analyst hours land where the risk actually is.

  3. 03

    Ship with controls

    Baseline controls attached, recommendations tracked, derogations formalized: the project ships, and security keeps the trail.

FAQ

Security by Design, in practice

Will this slow projects down?

The opposite is the design goal: routine initiatives flow through an assisted track in days, and the ones that warrant expert review get it earlier, when changing course is still cheap.

Who fills in the intake?

The project owner, in business language, guided by a wizard: a few minutes of context. The security translation, classification, baseline controls, analysis, happens on the platform side.

What happens to exceptions?

They become derogations: a formal register with justification, the right approval level, compensating mitigations synced to tickets, and an expiry date. No more acceptance by email.

Does it plug into CI/CD or scan code?

No. This is governance shift-left: risk decisions, controls and exceptions handled before and during build. It complements your engineering toolchain; it does not replace it.

BY DESIGN, VERIFIED

Bring one live project. Watch it get routed.

A live session: intake in business language, routing, baseline controls and the derogation path.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.