← Kenrick Tan / Back to work

Case study

Secure Supply Chain Pipelines

DevSecOps automation with policy-as-code, SBOMs, and artifact signing.

Delivered hardened CI/CD pipelines that bake in security checks without slowing teams down.

Impact

120+ pipelines standardized

Impact

100% SBOM coverage

Impact

Audit prep time cut by 60%

Impact

Zero critical vulnerabilities in production for 8 months

Impact

Policy compliance rate improved to 98%

Problem

Teams shipped in different ways, security controls were inconsistent, and audit evidence was piecemeal.

Architecture

Supply Chain Pipeline

Select a component to explore its role and connections.

123456

Commit

Signed commits + PR checks

Connects to: Build, Scan

Approach

  • Shipped reusable pipeline templates with SLSA-aligned checks.
  • Integrated secrets automation with HSM-backed Vault workflows.
  • Captured compliance evidence automatically at each stage.

Outcomes

  • Security is standardized without blocking teams.
  • Release approvals are faster with pre-collected evidence.
  • Engineering velocity increased while risk reduced.
  • Audit prep went from 2 weeks to 3 days.
  • Security team reviews reduced by 75% due to automated gates.

Metrics

Before → After comparison

Before

pipeline Consistency
23%
sbom Coverage
0%
audit Prep Time
2 weeks
critical Vulns Q1
12
policy Compliance
68%

After

pipeline Consistency
100%
sbom Coverage
100%
audit Prep Time
3 days
critical Vulns Q1
0
policy Compliance
98%

Stack

GitHub ActionsOPAVaultTerraform