Expert guidance to assess, design, and mature your secure development program; from the people who help write the standards.

Security expertise you can build
a program on
We work alongside your teams to understand how you build
software today, then make the secure path the path of least resistance.
Framework-backed, not opinion-based
Our analysis and roadmaps are structured on the OWASP SAMM framework, so results are measurable, defensible, and comparable against your peers.
Tailored to your culture
Recommendations align with your existing workflows and risk tolerance rather than fighting against them, so secure practices actually get adopted.
Faster delivery, lower risk
By focusing on the highest-impact gaps, we help you accelerate software delivery while reducing risk, not slowing teams down with process for its own sake.
Four ways we help you secure
your software
Engage us for a single assessment or an ongoing partnership. Each service
is tailored to your organization’s maturity, capabilities, and goals.
Secure Development Program Analysis
A structured assessment of your secure development lifecycle against the OWASP SAMM framework. We interview your teams, review your documentation, and score your maturity to produce a clear, prioritised roadmap for improvement.
Our approach
- Stakeholder interviews and documentation review across your program.
- Maturity scoring structured on the OWASP SAMM framework.
- A two-phase roadmap of recommendations, presented to your team.
Outcomes
- Objective maturity scores you can track and benchmark against peers.
- A clear, defensible plan for prioritising security investment.
- Faster delivery and reduced risk, focused on the highest-impact gaps.

Secure Architecture Review & Threat Modeling
An independent review of your application and system design, including data flows, integrations, and third-party services. We identify the highest-risk threats and provide concrete, practical guidance to address them.
Our approach
- Collaborative design sessions mapping components, data flows, and controls.
- Attack-path analysis with findings set out in a clear report.
- Delivered as a one-time model or a repeatable process your team can own.
Outcomes
- High-risk threats identified early, when they are least costly to fix.
- A shared, documented understanding of your architecture and controls.
- The capability to run threat modeling yourselves as systems evolve.

Process Development & Security Integration
We embed security into the way your teams already work — developing policies, standards, and risk and dependency management practices that blend automated and manual controls. Guidance is kept simple and measurable so it is genuinely adopted.
Our approach
- Policies, standards, and guidelines shaped around your existing workflows.
- A balance of automated and manual controls suited to your team.
- Clear, measurable guidance for both prevention and remediation.
Outcomes
- Secure practices that happen by default rather than by exception.
- Fewer vulnerabilities introduced, and quicker resolution of those that occur.
- Consistent security reviews that support delivery rather than slow it.

Security Training & Workshops
Practical, tailored training for your teams – from the OWASP Top 10 to threat modeling and beyond. Content is shaped around your technology and delivered in the format that suits your organisation.
Our approach
- Training scoped to your audience, technology, and learning objectives.
- Delivered in-person, as live workshops, or as recorded sessions for your LMS.
- Customised to your culture and internal requirements.
Outcomes
- Higher knowledge retention and real-world application.
- Demonstrable improvement in skills, beyond awareness.
- Consistent security knowledge across your teams.

Guidance from recognised leaders in
application security
You will be led directly by two of the most experienced practitioners in the
field; both active contributors to the OWASP frameworks the industry is built on.

Aram Hovsepyan
Founder & CEO, Codific · PhD, Application Security
Aram has spent over 15 years working in application security as a researcher, industry expert, and core contributor to the OWASP SAMM project, and is a founding board member of OWASP EU. He holds a PhD in application security from DistriNet KU Leuven, and his work on refining the LINDDUN privacy engineering methodology has been incorporated into both ISO and NIST standards.
Aram is also the founder and CEO of Codific, a cybersecurity company focused on application security and secure software development.

Brian Glas
Application Security Leader · VP of Consulting Services
Brian Glas has spent over 20 years working in information and application security as an engineer, program leader, and consultant, and is a long-standing contributor to the OWASP community. He is a project lead on the OWASP SAMM project and the SAMM Benchmark, and a core contributor to the OWASP Top 10 (2017, 2021, and 2025).
He has previously served on Microsoft’s Trustworthy Computing team and as Chair and Assistant Professor of Computer Science, teaching computer science and cybersecurity.
Organizations that rely on our consultancy
From global enterprises to fast-growing product teams, we’ve helped
organizations mature their secure development programs.







35+
Years of combined AppSec experience
OWASP
SAMM & Top 10 core contributors
ISO & NIST
Methodology adopted into global standards
Not sure where to start?
Tell us where things stand today and what you’re aiming for. We’ll help you identify the most
useful next step – an assessment, a threat model, or a tailored engagement.