Skip to content
All books
Stage 5 · Secure systems

Security is a feature

A free 15-page guide: why security is a product feature, what skipping it costs in 2026, and a 30-day plan with free tools.

About the book

Nobody asks most developers to build security. That is why it often arrives late, disconnected from ordinary engineering work and expensive to repair.

This free guide reframes security as a feature with acceptance criteria, tests and a small delivery loop.

It includes a zero-budget open-source tool stack and a four-week starter plan for developers, tech leads and small teams.

What you get

  • The four traits that define a feature, and where security falls short
  • What skipping it costs in 2026, with sources
  • The new threat surface: supply chain, AI-powered phishing, the OWASP LLM Top 10
  • Security as linting, unit testing and integration testing
  • A free and open-source tool stack, and a 30-day starter plan

A page from the book

Copied as printed, so you can judge the format before you buy.

Section 09, the plan, page 12

A 30-day starter plan

One month, four moves, no budget. Each week builds on the last and leaves you measurably safer than the week before.

Week 1 Get Visibility

• Turn on Dependabot (or Renovate) and your platform's code scanning in one key repo.

• Add Gitleaks as a pre-commit hook so no new secret can be committed.

• Generate one SBOM with Syft. You cannot protect what you cannot see.

Week 2 Build A Baseline

• Add Semgrep to CI with the default ruleset; triage, don't drown.

• Run Trivy against your dependencies and container images; fix the criticals.

• Write down a starting MTTR target for high-severity findings.

Week 3 Probe The Running App

• Run an OWASP ZAP baseline scan against a staging environment.

• Fix the top issues and re-scan to confirm they are actually closed.

• If you ship an LLM feature, test it against the OWASP LLM Top 10.

Week 4 Make It Stick

• Move secrets out of config and into a vault (Vault or Infisical).

• Reserve a standing security-debt budget in every cycle.

• Add "passes security checks" to your team's definition of done.

What is inside

  1. 01What makes something a feature
  2. 02Why security gets skipped
  3. 03What it costs in 2026
  4. 04The new threat surface
  5. 05Security as testing
  6. 06The payoff
  7. 07Where to start
  8. 08The free tool stack
  9. 09A 30-day plan
  10. 10Keep going

What readers say

  • “Idk why are there no reviews for this book?!!! This is is amazing. It made me think about security in a completely different way, and it's full of practical insights that every developer should know!!!”

    Nick R.
    Gumroad verified purchase

Reader reviews from Gumroad, word for word.

Who this is for

This is for you ifSecurity work stays abstract because nobody converted it into acceptance criteria and tests.

  • Software Developer
  • Tech Lead
  • Small engineering team
  • Team without a security budget
The library pathWhere this fits
  1. 01Get foundThe Silent Rejection
  2. 02Build the record and negotiateThe iOS Engineer playbook · Leverage
  3. 03InterviewThe iOS interview blueprint · The senior signal · Top 300 React Native interview questions · 500 Flutter interview questions · The senior SDET interview handbook
  4. 04Answer practice and live roundsThe 24-hour iOS interview answer book · The 24-hour Android interview answer book · Share your screen
  5. 05Architecture and qualitySwiftUI under load · Mobile System Design blueprint · Security is a feature · The second passYou are here
  6. 06Staff systems and ownershipAltitude · Ticket taker, outcome owner
  7. 07Build with AIBuild with your brain on (coming soon)
  8. 08LeadLeadership blueprint (coming soon)
  9. 09ArchitectArchitect blueprint (coming soon)
Portrait of Mike Salari

About the author

Mike Salari

Staff Mobile Engineer · Mobile Architect · Technical Author

I adapted and expanded this guide for 2026 because security becomes sustainable only when working developers can treat it as normal feature work.

15 years building production mobile software, with experience across Apple, Adobe, Cisco, Mastercard and Visa. 500+ technical interviews from the hiring side.

Read the full story

Before or after you buy

Not ready yet? Use the free security guide →

Already own it? Apply one testable security behaviour to the product you currently own.

Start with one testable security behavior.

Use the free guide to build a practical baseline without waiting for a security team or a new budget.

Share this book