EmberKat

Product security consulting

Product Security Consulting

As a product security consultant, EmberKat helps software companies build a product-security lifecycle that engineering can operate: secure development, vulnerability handling, customer evidence and accountable release decisions.

Discuss the scope
Typical durationUsually 3–6 weeks
Starting priceFrom €18,000 excl. VAT
Commercial basisWritten scope and proposal

Service definition

Put security inside the product lifecycle

The engagement connects product management, engineering, security and customer assurance around the product’s actual lifecycle, so security obligations are delivered with the product rather than assembled after release.

Scope

Work included in the scope

  1. 01

    Product-security lifecycle and governance review

  2. 02

    Secure development and architecture control assessment

  3. 03

    SBOM, dependency and vulnerability process review

  4. 04

    Coordinated vulnerability disclosure and PSIRT route

  5. 05

    Customer questionnaire and security-evidence operating model

  6. 06

    Release controls, ownership and product-security metrics

Client problems

Use this service when

  1. 01

    Product security is treated as a periodic assessment instead of a lifecycle.

  2. 02

    Engineering, product and customer assurance give different answers about readiness.

  3. 03

    A vulnerability disclosure process exists on paper but has not been exercised.

  4. 04

    Security evidence is recreated for every customer and every release.

Deliverables

Documents and decisions provided

  1. 01

    Product-security lifecycle and responsibility map

  2. 02

    Secure-development and release-control gap assessment

  3. 03

    Vulnerability disclosure and response operating model

  4. 04

    Customer evidence and assurance plan

  5. 05

    Prioritised implementation roadmap with owners

Common questions

Questions to settle before the work starts

Short answers to the questions that usually determine whether this is the right engagement.

What is product security consulting?
It is practical support for the security of software as a product: how it is designed, built, released, supported, monitored, disclosed and evidenced to customers or regulators.
Is product security the same as application security testing?
No. Testing is one input. Product security also covers ownership, secure development, dependencies, vulnerability response, release controls, customer evidence and the lifecycle after launch.
Does this apply to SaaS products?
Yes. The scope is shaped around the product and its delivery model, whether it is SaaS, an installed application, an embedded component or software used in a regulated device.

From the glossary

SBOMSoftware Bill of Materials
A list of every component inside a piece of software — an ingredients label, in a form a machine can read.
The full glossary

Related engagement

Cyber Resilience Act Consulting

Where the product is placed on the EU market, connect the lifecycle to CRA duties and technical evidence.

View engagement