What’s your opinion as a Customer? Should customers care about how the product is built, besides the value it provides?
Customer buying B2B product:
“ I got the value your product is offering & it’s awesome. But I want to know how your team built it. What #softwaresupplychainsecurity measures are you taking, what kind of security controls & updates, what tech stack & programming languages have you used, etc? Because I care about our environment, and when I bring your product into our network, I want to ensure security risks are low and well managed. “
Vendor’s answer (the details the Customer should look for):
“
We use X,Y,Z supply chain measures, #Securecontainers, we enhanced our risk reduction process with #webassembly and #secureKubernetes ecosystem, we follow #TDD & #TestOps, #GITOPS and #chaosengineering to keep our apps and infra reliable and well managed to reduce risks, we do have automated #vulnerabilitymanagement in place which we run every day, we do #fuzztesting and #pentesting, we use AI to automate a lot of our workloads so that we can release thoroughly tested and up-to-date secure versions of our product almost every day or at least once a week, we publish our vulnerability reports to public to keep transparency, we even opensourced our code base for transparency, etc.
“
Isn’t this what makes final decision of a Customer very confident? Shouldn’t this be your primary decision making point as a Customer?
Smart Contract Security | Fuzzing | Web3 | Blockchain | Crypto | Automation | AI | Application Security | Automotive Security | Embedded Security | Cybersecurity
1wLooks like Blink Ops can offer a lot in automating API security!