Back to event recap
    Founder’s Playbook

    Treating application security as a continuous engineering capability

    Divakar Prayaga · PurpleLens

    August 12, 2026Hacker Dojo, Mountain View
    Divakar Prayaga presenting PurpleLens at the StartupA2Z event

    01 · The problem

    Why does end-of-cycle security testing fail fast-moving teams?

    AI-assisted development helps teams ship faster, while increasingly automated attacks make periodic, end-of-cycle security testing harder to rely on.

    • AI-assisted development helps teams ship code faster.
    • Attackers increasingly automate discovery and exploitation.
    • Periodic testing can identify problems only after they have become expensive release blockers.

    02 · The solution

    Move application-security testing into the development lifecycle.

    Divakar explained why application testing needs to run continuously through the development lifecycle instead of remaining a final checkpoint before release.

    03 · What was demonstrated

    Security as a continuous engineering capability

    The talk broke the approach into a practical sequence:

    1. 1Test throughout development
    2. 2Find weaknesses before release
    3. 3Return findings to engineering quickly
    4. 4Repeat as the application changes

    04 · The founder take

    Security must move at product-development speed

    For startups, security problems found after customers arrive can become product, compliance, and reputation problems. Build security into engineering before it becomes an emergency response.

    Shift feedback earlier

    Security findings are easier to fix before customers and deadlines are involved.

    Treat security as engineering

    Continuous testing belongs inside the product lifecycle, not outside it.

    Prevent business impact

    Late security failures can become product, compliance, and reputation problems.