717 DEV

Application & AI Security · Software Security Assurance · Security Engineering

Software security you can build, test, and prove.

717 DEV helps software organizations secure applications and AI systems, operationalize secure development, and produce defensible evidence for customers, regulators, and leadership.

Assess Your Software Security Program Review a Product or AI System
How the Work Fits Together

One System, Three Practices

Plenty of firms will test your application and hand you a PDF. We assess the software and the program that produced it, then stay to build the fixes and confirm they hold.

Step 01

Assess

Test the product and examine the program behind it: architecture, code, pipelines, ownership, and the evidence sitting behind each control.

Step 02

Identify Gaps

Separate what is missing from what exists but cannot be demonstrated. Both are gaps, and they need different fixes.

Step 03

Implement

Build the controls, automation, and architecture changes. Engineering work in your stack, not a list of recommendations.

Step 04

Validate

Re-test, re-examine, and confirm the control operates. A gap closes on evidence, not on assertion.

How the three practices connect Application and AI Security tests the software and passes findings to Software Security Assurance, which evaluates the program and assembles the evidence. Assurance passes prioritized gaps to Security Engineering, which implements the controls. Engineering output returns to Application and AI Security for validation, closing the loop. Application & AI Security Is the software secure? Software Security Assurance Can you prove it? Secure Engineering Who builds the fix? Validate, then start the next cycle from evidence
Findings feed the program view. The program view sets the build order. What gets built comes back for validation.
Core Practices

Three Practices, One Company

Each answers a different question. Together they cover the software, the program that builds it, and the work of fixing both.

Is the software secure?

Application & AI Security

Find and reduce risk in the software itself.

  • Application Security Assessments
  • AI and LLM Security Reviews
  • Penetration Testing
  • Threat Modeling
  • Security Architecture Reviews
  • Source Code Reviews
  • Software Supply-Chain Reviews
  • Adversarial Security Testing
Explore Application & AI Security
Can you prove it?

Software Security Assurance

Build a defensible software-security program and prove that it operates.

  • Software Security Evidence Readiness Assessment
  • Secure Development Program Assessment
  • Secure SDLC Program Design
  • NIST SSDF Readiness
  • OWASP SAMM Assessment and Operationalization
  • Customer and Regulatory Readiness
  • Product Security Program Development
  • Fractional Product Security Advisory
Explore Software Security Assurance
Who builds the fix?

Security Engineering

Turn security recommendations into working controls.

  • DevSecOps Implementation
  • CI/CD Security
  • Security Automation
  • Secure Architecture Design
  • Remediation Engineering
  • SBOM Automation
  • Software Supply-Chain Controls
  • Security Tool Integration
Explore Security Engineering
Who This Is For

Organizations

  • Software companies and SaaS providers
  • AI companies and teams shipping LLM-backed features
  • Technology organizations with software in the critical path
  • Product manufacturers with software or firmware in the product
  • Companies selling software into enterprises or government
  • Organizations affected by software-security regulation

Who usually brings us in

  • CISO, CTO, and CIO
  • VP and Director of Engineering
  • Head of Product Security or Application Security
  • Security engineering and platform leadership
  • Product leadership answering customer security reviews
  • Founders and executives preparing for diligence
Flagship Assessment

Can you prove how your software is secured?

Owning security tools is not the same as running a program, and running a program is not the same as being able to show it. The second thing is what gets asked for, usually on a deadline, usually by someone who can hold up a deal.

  • Enterprise customers
  • Regulators
  • Government purchasers
  • Executives
  • Boards
  • Auditors
  • Business partners

The Software Security Evidence Readiness Assessment examines how your organization governs, performs, and evidences software security across roughly thirty areas, from threat modeling and secure coding through SBOM processes, release integrity, and vulnerability disclosure. You get a scored picture, a gap analysis mapped to public frameworks, and a roadmap sequenced to the work required.

Discuss an Assessment
Selected Engagement

What the Work Actually Looks Like

Anonymized at the client’s request. Sector and scale are indicative, findings are described without identifying the system.

See all four engagements

Standards Participation

Founder Matthew Houseman serves as editor of ISO/IEC PWI 26688, Application Security Market Analysis. 717 DEV is independent and is not endorsed by any standards body.

OWASP Community

Work in the OWASP community on application and AI security, alongside the open projects our assessments draw on.

Get in Touch

Start a Conversation

Whether you are scoping an assessment, preparing for a customer security review, or trying to work out where the gaps are, tell us what you are dealing with.

Reach us directly.

Tell us what you're working on. Most inquiries receive a response within one business day.