Practical guide · 6 min read
Software assurance: make the product evidence usable
A practical operating model for secure releases, vulnerability response, and EU Cyber Resilience Act readiness.
Read the practical guideConnect product evidence with what buyers and regulators need.
Product assurance joins engineering evidence with the claims an organization makes to customers. Start with a product version, follow its release and vulnerability history, and make the support obligation visible to the people who own it.
Start with a question
Practical guide · 6 min read
A practical operating model for secure releases, vulnerability response, and EU Cyber Resilience Act readiness.
Read the practical guidePractical guide · 5 min read
Build a decision around operating costs, required capabilities, and testable risk reduction. Make every assumption visible.
Read the practical guideField note · 5 min read
A proposed approval pattern that preserves a binding decision and the full review record for trust lists, signing releases, and other consequential changes.
Read the field noteGuide · 7 min read
A practical architecture for provisioning, attestation, signed updates, recovery, and evidence across the life of a connected product.
Read the guideGuide · 7 min read
Connect model releases, agent authority, data provenance, and runtime evidence so an AI system can be evaluated, constrained, and stopped.
Read the guideOne word in Microsoft’s revision note caught my eye: “informational.” The underlying change was anything but routine. Microsoft had published CVE-2026-69836 as an exploited…
The question after the July 29, 2026 2026 Minimum Elements for a Software Bill of Materials update is not whether every software company must sign an SBOM. The joint guidance,…
Another week, another version of the same story. Eduard Kovacs at SecurityWeek reported that three recently patched Fortinet FortiSandbox vulnerabilities (CVE-2026-39808,…