Security Belongs in the Platform

Shift-down security moves essential protections into the platform itself. In Episode 5 of Platform Engineering 2.0, Alan Shimel and Broadcom’s Pankaj Gupta explore that approach. The discussion focuses on the fourth pillar of the framework: making security a built-in capability rather than another developer burden.

Gupta presents this evolution as a complement to shift-left practices, not a replacement. Early testing still helps teams find problems during development. However, production environments introduce changing configurations, runtime risks and threats that pre-deployment checks may miss.

Make Secure Defaults Part of Delivery

The conversation turns to controls that platform teams can implement and govern centrally. Gupta highlights least privilege, mutual TLS, microsegmentation and automated secrets rotation. These protections should support secure deployment without requiring every developer to configure them independently.

Security as code and continuous compliance extend that foundation. Rather than treating compliance as an occasional review, Gupta argues for controls that remain active throughout delivery and operation. Runtime protection continues the work after applications reach production.

This approach also addresses cognitive load. Developers can focus on building applications while the platform supplies consistent guardrails. Security teams still define requirements, but those requirements become part of the system developers use.

AI Expands What Platforms Must Protect

AI introduces additional concerns, including prompt injection, model poisoning and inference data leaks. Gupta explains why platform responsibilities now extend beyond applications to models, data and inference. The platform becomes a boundary for trust across those resources.

He identifies model registry governance and strong data isolation as practical starting points. AI and MCP gateways can also support prompt controls and inference auditing. The objective is to make protections platform-managed and ready for audit by default.

The episode closes by examining an important tension: secure foundations must remain dependable while threats keep changing. Gupta emphasizes that immutability does not mean standing still. Defenses need ongoing improvement, and security remains a shared responsibility across the organization.

For platform teams, shift-down security offers a way to connect developer productivity with stronger governance. The challenge is to keep those protections current as platforms and AI workloads evolve.