Skip to content
DipanshuTechBuilding Digital. Driving Growth.

Technology

SecurityThreat Model, Guardrails, Audit

The security stack we reach for, the trade-offs we name, and when we use something else — threat modelling as the first conversation, guardrails as the architecture, the audit trail as the requirement, with the controls built for the compliance posture the business needs.

What we use it for

Threat modelling as the first conversation — the threats, the mitigations, the residual risk. Guardrails as the architecture — the input filters, the output filters, the structured output validation. The audit trail as the requirement — every action stamped with the user, the inputs, the outputs and the timestamp.

We extend the stack with the tools the compliance posture needs — a WAF (Cloudflare, AWS WAF), a secrets manager (AWS Secrets Manager, HashiCorp Vault), a log store (CloudWatch, Datadog), an SBOM generator, a dependency scanner.

When we choose it over the alternative

We choose a managed WAF when the workload is public and the WAF rules are well-known. We choose a secrets manager when the secrets are many and the rotation is regular. We choose a managed log store when the volume is moderate and the cost is acceptable. We choose an SBOM generator and a dependency scanner when the compliance review expects them.

The right answer depends on the threat model, the compliance posture and the team. We will say so on the call, with a written rationale for the choice and the trade-offs named.

When we do not choose it

We do not choose a custom WAF when the managed WAF is good enough and the team does not have the operational capacity to run it. We do not choose a self-hosted secrets manager when the managed one is the right answer for the team. We do not choose a self-hosted log store when the managed one is the right answer for the cost.

Frequently asked

The questions the team asks

What is the minimum security baseline?
Secrets in a secret manager, dependency hygiene automated, audit log on the critical records, input validation, output validation, the WAF in front of the public app, the access control reviewed quarterly. The baseline is the floor, not the ceiling.
Do you do penetration tests?
We help you prepare for an external penetration test, and we can recommend the right vendor. The penetration test itself is a separate engagement, with a written report, the remediation list and the follow-up test.
How do you handle the DPDP Act 2023?
The architecture is built to comply: consent capture, data minimisation, purpose limitation, retention rules, the right to erasure, the breach response. The compliance is part of the build, not a wrapper, and the audit log records the consent and the breach response.

Have a project in mind?Let’s scope it together.

Tell us the outcome you need. You get an approach, a rough timeline and next steps within one business day.