Security by design

Application security services for R&D teams

From SSDLC maturity to EU CRA compliance, we help your teams build secure-by-design products.

Trusted by

Our services

SSDLC Maturity Assessment & Roadmap

  • Assess your current practices
  • Prepare a roadmap to meet EU CRA and other regulations
  • Turn assessment findings into practices teams can run themselves
  • Create policies and documentation for legal evidence
See more
SecureHabits services: assessment, training and architecture guidance working together

Training for R&D Teams

  • Practical Threat Modeling workshops
  • Hands-on Secure Coding training
  • Train developers to apply security in daily work
See more

Cybersecurity Architect as a Service

  • On-demand guidance for complex projects
  • Embed security into architecture from the start
  • Flexible expertise without long-term lock-in
See more

Get a free EU CRA compliance strategy health check from us

Our approach

We strengthen application security with assessments, guidance, and training that fit into your delivery process.

  • Assess

    Understand your current maturity and risks

  • Build

    Train, coach, and turn agreed controls into daily work.

  • Hand over

    Hand over security routines your teams can run without us

Security that stays
after we leave

Security in daily work

We bring threat modeling into design work, and secure-coding guidance into implementation, review, and release preparation.

People and culture

Developers, architects, product owners, and security champions practice writing security requirements, reviewing risky flows, and assigning follow-up work.

Security as a habit

Your teams keep using threat modeling, secure-coding guidance, and roadmap reviews after the engagement ends.

Our partners

All-in-one AppSec platform for software supply chain security

Application security maturity management platform

Developer-centric application security training platform

Katilyst equips security champions to run engagement programs and reinforce secure behavior.

Securing guides teams through scoping, testing, report review, and remediation.

Offensive security, threat detection, incident response, and security operations for regulated and high-risk environments.

Our team

Nariman Aga-Tagiyev

Nariman Aga-Tagiyev

Application Security Architect

Application Security Architect. CSSLP, OWASP SAMM core team member, ISO 27034 liaison, threat modeling coach, and secure coding coach.

LinkedIn →
Azadeh Haratiannezhadi

Azadeh Haratiannezhadi

Professor & Researcher, AI and Cybersecurity

Professor and researcher working where AI, cybersecurity, and international standards converge. PhD in Cognitive Science Modeling, a Master’s in AI, and 15+ years of experience turning complex technologies into usable, human-centered systems.

LinkedIn →
Max Alejandro Gómez-Sánchez Vergaray

Max Alejandro Gómez-Sánchez Vergaray

AppSec Program Leader

AppSec Program Leader with 10+ years of experience in banking and finance. CSSLP and CISM certified, active OWASP contributor, and trainer in DevSecOps, S-SDLC, secure design, and threat modeling. He works with teams to secure software from design to delivery.

LinkedIn →
Timo Pagel

Timo Pagel

DevSecOps Architect

Timo Pagel is a DevSecOps architect with 25+ years of experience who integrates security into development lifecycles, leads OWASP projects, and provides security training and consulting.

LinkedIn →
Luc Poulin

Luc Poulin

Senior Application Security & Trustworthiness Advisor

Luc Poulin is a veteran application security expert with a doctorate in software engineering and over four decades of experience in IT. He specializes in integrating and auditing security throughout the application lifecycle and contributes internationally to ISO/IEC standards, including as lead editor of ISO/IEC 27034.

LinkedIn →
Eden Yardeni

Eden Yardeni

Application Security Architect

Eden Yardeni has built application security programs across several large enterprises. A software engineer by background, she joined the OWASP ASVS working group in 2024 and specializes in security champions programs, threat modeling, and secure software development lifecycles (SSDLCs).

LinkedIn →

Ready to make security second nature for your teams?