Overview
Codific is a secure software development company that builds HR-Tech, Ed-Tech, and Medtech collaboration tools leveraging security by design and privacy by design principles.
Key people
In the news
- Supplier risk management just got a serious upgrade in #SAMMY. 📋 The feature now enables more complete management of supplier risk. What's new: → A full supplier inventory; status, criticality, points of contact, and all the information you need in one place → Everything you need to demonstrate supplier oversight for ISO certifications, without digging through spreadsheets → Send assessments directly to suppliers from within SAMMY → Review completed assessments with a validation workflow, give feedback, flag gaps, and request
- Real AppSec leaders. Real assessments. Real stories. The OWASP SAMM & DSOMM User Day is heading to San Francisco on November 4, alongside OWASP® Foundation Global AppSec USA. Some of the most valuable talks at these events come from real assessments, real roadmaps, and the challenges that came with them. If you have a story worth sharing with the community, this is the place. Last submission window closes September 15. Getting accepted also gets you a full conference pass. 🎟️ 🔗 Submit your talk: https://lnkd.in/ehdfG-WF
- SAMMY now connects directly to your #LLMs. 🤖 Ask questions about your own security data, directly without exporting reports, or switching tools. It takes two minutes to set up. Once it's done, you can ask #specific questions about your own assessments and get real answers back. In our demo, we asked for an executive report on the state and roadmap of a business unit, based on the latest SAMM assessment. We got the full report back in minutes. Works with Claude, other LLMs, or a locally hosted model if you'd rather keep everything
- This week, #CRA reporting obligations become #law. 📜 ⚖️ If you're still piecing together what that means for your team, here's a good place to catch up. CEO Aram H. and Legal Expert Lara Brito have been breaking down the regulation episode by episode, translating it into what product teams actually need to do. A few things worth knowing before Thursday: → CRA splits products into categories with very different levels of scrutiny; knowing yours is the first step → Risk can't be assessed by engineering alone. It needs business
- T-8 days until the #CRA reporting obligations kick in. ⏳ Reporting to ENISA sounds simple. Submit a notification, done. In practice, it's a three-stage process with hard deadlines at each step: 1️⃣ 24 hours: Early Warning Notification, once you have credible evidence of active exploitation 2️⃣ 72 hours: Vulnerability Notification, with general technical detail as available. 3️⃣ 14 days after a fix is available: Final Report, which closes the case permanently Miss the first deadline and an unsubmitted draft doesn't count. The clock
- If you're still not sure whether #CRA applies to your product... we need to talk 😅 Reporting obligations start September 11. The"I'll figure it out next week" won't work... The good news is; figuring out if CRA applies to you doesn't have to be complicated. A few questions, and you'll know exactly where your product stands. We built a #free CRA scope checker in #SAMMY to help you do just that. 🔗 https://lnkd.in/emxAVtT7 No judgment if you're checking this in the final stretch. Better now than September 12. 👇
- Security #training your team remembers - not another click-through course. From the OWASP Top 10 to threat modeling and beyond, we build training around what your teams really need. 📍 Delivered your way: in-person, live workshops, or recorded for your LMS 🎯 Tailored to your tech and your organisation 🔁 Built for retention so it changes behaviour, not just checks a box ▶️ Watch Brian close out the series below. Inside Codific's Consultancy Services · 4 of 4 🎓 See all four services → https://lnkd.in/eWw6nW3E
- You're right; we need to build this in." So what happens after a #SAMM assessment? That's usually where this service begins. Common next steps: 🔹 Threat modeling in the design phase 🔹 Security tooling and checklists in CI/CD 🔹 Policies, processes, and secure requirement standards Can you do it yourself? Absolutely, many teams can. But when you bring us in, we've already learned your culture through the assessment. That means faster, smoother integration. The aim: make secure practices happen by default, not by exception. ▶️
Alumni 1 went on to found or lead
Dag FlachetInvestor and Partner→Founder and Managing Partner at Flachet Holdings NV
Something wrong or missing? Send an update. Fixed within 24 hours.







