Compliance
Secure Development Lifecycle
For a cybersecurity company, how we build and deploy software is itself a security statement. eNeoteric's Secure Development Lifecycle (SDL) embeds security controls at every phase of software delivery — from requirements and design through testing, deployment, and operational monitoring — ensuring the tools and platforms we build for customers meet the same standards we audit others against.
Our SDL phases
Phase 1 — Security requirements
Security requirements are defined alongside functional requirements at the start of every project. We use threat modelling (STRIDE methodology) to identify security objectives, trust boundaries, and potential attack vectors before a line of code is written.
Phase 2 — Secure design
Architecture reviews include a security design review against OWASP Application Security Verification Standard (ASVS) Level 2 as a baseline. Data flow diagrams are annotated with trust boundaries and security controls. Third-party component selection includes a licence and vulnerability review.
Phase 3 — Secure coding
Developers follow OWASP Secure Coding Practices. Static Application Security Testing (SAST) is integrated into the CI pipeline (Semgrep, Bandit for Python, SonarQube for Java/JavaScript). Secret scanning (Gitleaks, GitHub Advanced Security) prevents credential commits. Code review includes a security checklist for authentication, authorisation, input validation, and error handling.
Phase 4 — Security testing
Dynamic Application Security Testing (DAST) runs against staging environments using OWASP ZAP. Software Composition Analysis (SCA) identifies vulnerable dependencies (Dependabot, Snyk). Pre-release security testing by our internal security team covers OWASP Top 10, business logic, and API security.
Phase 5 — Secure deployment
Production deployments follow a hardened configuration baseline. Infrastructure is provisioned as code (Terraform/Ansible) with security controls version-controlled. Container images are scanned before deployment. Secrets are managed via a dedicated secrets management system — never hardcoded.
Phase 6 — Monitoring and response
Production applications are monitored for security anomalies using application-level logging integrated with our SIEM. Dependency vulnerabilities are monitored continuously and patched per our vulnerability management SLAs. Annual penetration tests cover all customer-facing systems.
Frequently asked questions
- Does eNeoteric follow OWASP guidelines in its development?
- Yes. Our SDL incorporates OWASP guidance throughout — OWASP Top 10 and WSTG in security testing, ASVS for design review, Secure Coding Practices for developer guidance, and the OWASP Dependency Check/SCA toolchain for third-party component risk.
- How do you handle security vulnerabilities found in your own software?
- Vulnerabilities identified through our SAST/DAST tooling, penetration testing, or responsible disclosure are tracked in a security backlog, triaged by severity, and remediated per the SLAs in our Vulnerability Disclosure Policy. Critical vulnerabilities in production systems are addressed within 7 days.
- Can customers request evidence of SDL compliance?
- Yes. Enterprise customers can request our SDL documentation, SAST/DAST scan summaries, and penetration test executive summaries as part of vendor due diligence. Contact [email protected] with subject 'SDL Evidence Request'.
- Do you train developers on secure coding?
- Yes. All developers complete OWASP-based secure coding training annually, with role-specific training for those working on authentication, payment, or healthcare data systems. Senior developers complete a security champion programme that covers threat modelling, code review for security, and security testing tool operation.
Questions about our secure development practices?
Contact UsGet in touch
Request a Callback
Drop your details and we'll call you back within one business day — or reach us on +91 91080 15170.