← Kenrick Tan / Back to work
Case study
Secure Supply Chain Pipelines
DevSecOps automation with policy-as-code, SBOMs, and artifact signing.
Delivered hardened CI/CD pipelines that bake in security checks without slowing teams down.
Impact
120+ pipelines standardized
Impact
100% SBOM coverage
Impact
Audit prep time cut by 60%
Impact
Zero critical vulnerabilities in production for 8 months
Impact
Policy compliance rate improved to 98%
Problem
Teams shipped in different ways, security controls were inconsistent, and audit evidence was piecemeal.
Architecture
Supply Chain Pipeline
Select a component to explore its role and connections.
Commit
Signed commits + PR checks
Connects to: Build, Scan
Approach
- Shipped reusable pipeline templates with SLSA-aligned checks.
- Integrated secrets automation with HSM-backed Vault workflows.
- Captured compliance evidence automatically at each stage.
Outcomes
- Security is standardized without blocking teams.
- Release approvals are faster with pre-collected evidence.
- Engineering velocity increased while risk reduced.
- Audit prep went from 2 weeks to 3 days.
- Security team reviews reduced by 75% due to automated gates.
Metrics
Before → After comparison
Before
- pipeline Consistency
- 23%
- sbom Coverage
- 0%
- audit Prep Time
- 2 weeks
- critical Vulns Q1
- 12
- policy Compliance
- 68%
After
- pipeline Consistency
- 100%
- sbom Coverage
- 100%
- audit Prep Time
- 3 days
- critical Vulns Q1
- 0
- policy Compliance
- 98%
Stack
GitHub ActionsOPAVaultTerraform