Controls
- Role-based access with least privilege and quarterly access review
- Mandatory peer code review before merge
- Dependency, secret and container scanning enforced in CI, failing closed on critical findings
- Annual third-party penetration testing with remediation tracked to closure
- Published responsible disclosure channel