Security by Design
If we want software — written by people or by agents — to meet security expectations, those expectations have to exist somewhere: stated, scoped to the risk at hand, and citable. This track is about building that body of knowledge and delivering it where the work happens.
The SbD-ToE manual
An SDLC-wide security-by-design manual — from application classification and requirements through architecture, dependencies, secure development, CI/CD, infrastructure-as-code, containers, deployment, monitoring and governance — organised as governed entities: controls, requirements, user stories and checklist items with stable, citable identifiers and risk-level applicability.
The programme is registered on OSF: DOI 10.17605/OSF.IO/7T849.
AppSec Core — the ontology
A small, principled vocabulary into which heterogeneous external sources — NIST SSDF, CIS, OWASP, SCF, NIST 800-53 and others — are normalised, so that "what applies here, and why" has one answer with provenance instead of five overlapping checklists.
The MCP server
A Model Context Protocol server exposes the manual to AI coding agents. Given a task and a risk level, it returns the activated scope: the applicable requirements, with citations, phrased for the moment of implementation. The payload is what and when — never exploit examples. The same mechanism serves humans: role guides, implementation checklists, verification matrices.
Open core
The manual and its tooling are open. Organisations that want their own policies, exceptions and evidence layered on top run a private overlay served through the same MCP interface — your knowledge, composed over a governed core. That commercial layer lives at ShiftLeft.