Skip to content
All services
DevSecOps & secure CI/CDBuild

Secure CI/CD pipeline

A pipeline that scans every change, builds each image once, promotes it by digest and asks for approval before production, for one app in 2–3 weeks or up to 10 repositories in 4–5 weeks.

When you need it

Every team builds and deploys in its own way. Some pipelines run scanners and most do not, production deploys go out with nobody looking, and security findings arrive after release, when they cost the most to fix.

What sets the quote

  • Starter, 2–3 weeks: one app or monorepo on one CI platform, up to 3 environments and one deployment target.
  • Standard, 4–5 weeks: up to 10 repositories on one CI platform, with preview environments for up to 3 apps.
  • A deployment target is one runtime, such as a Kubernetes cluster, Amazon ECS, Azure Container Apps or Cloud Run.
  • Gates use open-source tools or tools you already license.
  • Larger estates are quoted after the call.

What changes

  • Every change passes the same gates for code, secrets, dependencies, infrastructure code and images before it merges.
  • Production runs exactly what was tested, because each image is built once and promoted by digest.
  • Production deploys need an approval, and every deploy leaves an audit trail.
  • With Standard, every new repository starts from shared templates and organisation rules.

What you get

  • Pipeline as code in your repository, deploying to your cloud with OIDC instead of stored keys
  • Security gates: SAST (Semgrep or CodeQL), secrets (Gitleaks or platform secret scanning), dependencies (OSV-Scanner or Trivy), infrastructure code (Checkov or Trivy) and images (Trivy or Grype)
  • An SBOM for every build, for example with Syft
  • Build once and promote by digest through up to 3 environments, with an approval before production
  • Agreed thresholds and one decision record for every gate
  • Standard only: shared pipeline templates and organisation rules for every repository in scope
  • Standard only: image signing and verification, preview environments for up to 3 apps and one findings dashboard
  • Handover session and a runbook for your team

Starter suits one product team that needs a safe path to production. Standard suits an engineering organisation that wants every repository on the same rules, and it combines well with software supply chain security, which adds signed build provenance and deploy-time checks. A pipeline security check is often the first step.

Not included

  • Fixing the vulnerabilities the gates find
  • Containerising an app that does not yet run in a container (quoted separately)
  • Licences for commercial scanners
  • Signed build provenance, a base-image policy and automated dependency updates (see software supply chain security)
  • Penetration testing (we can refer you to a certified partner)
  • Running the pipeline after handover (available as a care plan)

What we need from you

  • Admin rights on the repositories in scope and permission to create pipelines, environments and runners on your CI platform, for example Admin on GitHub or Maintainer on GitLab.
  • Rights to create keyless deployment identities in each environment: IAM roles and an OIDC identity provider on AWS, Managed Identity Contributor and Role Based Access Control Administrator on Azure, IAM Workload Identity Pool Admin and Project IAM Admin on Google Cloud.
  • A tech lead for each app, about 2 hours a week, for decisions on gates and thresholds.
  • A named approver for production deploys.

How it works

  1. Free 30-minute call, then a written fixed quote based on your repositories, environments and deployment targets.

  2. Design session to agree branching, environments, gates, thresholds and approvals.

  3. Build the pipeline as code; you review every change as a pull request.

  4. Run the gates in warning mode, tune out false positives, then make them blocking.

  5. Handover session, runbook and decision records.

At a glance

Duration
2–5 weeks
Price
Fixed quote after a free 30-minute call
Delivered by
Our lead architect and a cloud engineer
Assess

DevSecOps gap check

In 1–2 weeks, a check of how your teams build and ship software, scored against OWASP SAMM and NIST SSDF, ending in a gap list and a 90-day plan.

Duration:1–2 weeks
Assess Popular

Pipeline security check

A one-week review of one CI/CD platform, from organisation settings to runners and secrets, with findings mapped to the OWASP Top 10 CI/CD Security Risks and SLSA.

Duration:1 week
Build

Keyless pipelines and secrets cleanup

Your pipelines move from long-lived cloud keys to short-lived federated tokens, with secret scanning and dependency gates that stop new leaks and risky dependencies before merge.

Duration:1–3 weeks

Not sure where to start?

Book a free 30-minute call. We learn what you need and tell you honestly whether and how we can help. There is no obligation.