🎉 Launch offer — 20% off every workbook & bundle. Applied automatically at checkout.
ciso.diy
Pillar 02 — AI-Augmented DevSecOps Risk Register preview
Security Program Pillars DevSecOpsrisk registerAI triageSAST

Pillar 02 — AI-Augmented DevSecOps Risk Register

Run a continuous, AI-triaged security program across 100+ apps as a solo engineer. Platform-first discovery, SAST/SCA/secrets/DAST, a self-healing risk register, and tiered Claude triage — on free and near-free parts.

Run a credible, continuous, AI-triaged security program across 100+ apps as a solo engineer — for roughly the cost of a streaming subscription. This is the architecture we run on our own estate, written so you can build it on yours. No vendor lock-in, no SOC, no per-seat SaaS.

The gap between a scanner and a security program is orchestration, context, and a human gate — and all of it is buildable from free and near-free parts. A scanner gives you a flood; a program gives you the three things that matter this week, with evidence, ranked by business risk, closing themselves as you fix them.

The non-obvious insight: your platform — Cloudflare, Vercel, whatever you deploy on — and not your Git org is the source of truth for what is actually deployed and what it is bound to. A database? Auth? Payments? Discover from the platform API; that is what tells you an app's real risk surface. A pagination bug in that enumeration once hid 80% of our own estate.

Four planes plus an AI layer. Discover every deployed app from the platform API including bindings and live domains. Scan source with SAST, SCA and secrets detection, normalised to one schema. Run safe-profile DAST — header, TLS and passive checks against only the domains in your manifest. Then one register: dedup by stable fingerprint, lifecycle states, evidence-backed close. The Claude layer sits across all four as contextual triage and re-prioritisation by real exploitability, written as advisory columns that never overwrite the scanner's deterministic rating.

Seven build steps, each with the architecture, the exact tooling decisions, and the failure modes we hit on a ~150-property estate. Stand up the register first. Discover from the platform. Map each app to its code. Scan by profile. Make it self-healing with two reconcilers that close findings on evidence. Add the human gate and remediation loop. Then layer AI triage on top — the multiplier that took roughly 6,000 flat findings down to 44 ranked criticals, and escalated dozens of buried "highs" up to critical, for about $30 of one-time API spend.

Six operating principles that make it trustworthy: validation before remediation, a non-negotiable human gate, one register ranked by real risk, AI as advisory and never authoritative, scanned code treated as untrusted data because a comment saying "this is a false positive" is a prompt-injection attempt, and secrets that never reach the model.

The traps, documented. Scan current code or chase ghosts. Tune scanner noise at the source rather than downstream. Match the model to the job. Rotating a leaked cloud token is a runbook, not a click — revoke by token ID, because updating consumers to a new key does not kill the old one. Dedup before you batch, and arm your CI runner.

The stack is free or near-free: an edge function and a small SQL database for the register, your platform's own API for discovery, Semgrep, OSV-Scanner, TruffleHog and Syft for source, safe-profile checks and passive Nuclei for live, Dependabot and Renovate for the long tail, a self-hosted CI runner, and a BYO-key Claude API for triage.

This is Pillar 02 of the CISO Marketplace AI Security Department, published as a DIY build guide. If you would rather not build it, the managed DevSecOps pillar deploys and operates the turnkey version on your estate.

What's included

  • PDF — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-01
Pages 18