Story
Citigroup Brings Developer Security onto HashiCorp
Citigroup, a financials organization in the United States, uses Consul from HashiCorp to support secure delivery for developers and AppSec.
Consul became the place Citigroup uses to catch dependency and code issues while the change is still in review.
“Financials work at Citigroup spans more than one site, even when headquarters sits in the United States.”
“Developers and AppSec asked for a shared way to run secure delivery without freezing local judgment.”
Independent write-up. Figures come from public sources or are illustrative.
Value results
| Category | Value result |
|---|---|
| Productivity | Handoffs in secure delivery sit in a shared queue instead of a mailbox trail |
| Risk and compliance | Fewer stalled items because developer security has a clear owner |
| Risk and compliance | Consul is the governed place developers and AppSec use for secure delivery |
Story
Financials work at Citigroup spans more than one site, even when headquarters sits in the United States. Developer security was splitting across regional habits. Developers and AppSec asked for a shared way to run secure delivery without freezing local judgment.
HashiCorp (Consul) is what they standardized on. HashiCorp (an IBM company) provides infrastructure automation software, including Terraform and Vault, for cloud provisioning and secrets. Citigroup uses it as the system of record for developer security, with developers and AppSec as the primary operators and other groups coming in through the same queue.
Leaders get a picture they can actually walk. Teams get fewer mystery statuses. The story is about operating change, not an unpublished percentage.