Our Story

Pioneering DevSecOps Automation

AppSecFastTrack was founded after its founder spent many years working across software development, solution architecture and cybersecurity in the Australian Federal Government and other regulated environments. The same challenge appeared repeatedly. Organisations understood their application security and compliance obligations but were constrained by fragmented tools and limited specialist resources, resulting in DevSecOps implementations that could take months to complete.

The team recognised the need for a fundamentally different approach: one that could get a DevSecOps pipeline working in 15 minutes, not months, without disrupting developers or requiring organisations to build and maintain every integration themselves. SAST, DAST, SCA, application monitoring and compliance evidence needed to work together rather than as separate activities.

This led to the creation of AppSecFastTrack, a DevSecOps automation platform that establishes a working security pipeline in approximately 15 minutes. By bringing SAST, DAST, SCA and APM into one workflow, it helps teams identify and prioritise vulnerabilities earlier, streamline remediation and produce compliance-aligned evidence for frameworks including PCI DSS, the Australian ISM, ISO 27001, the EU CRA, SOC 2, CIS Controls and NIST SSDF.

Meet Our Founder - Phillip Vu

Phillip Vu is the Founder and CEO of AppSecFastTrack. A CISSP-certified cybersecurity professional and former Cisco architect, Phillip has spent more than 23 years working at the intersection of hands-on software development, solution architecture, AI, cloud technology and application security within complex and highly regulated environments.
Phillip and his wife (Minsi Hong) created AppSecFastTrack in response to the real-world difficulties organisations face when implementing DevSecOps. Hundreds of security scanning tools are available, but connecting them to DevSecOps pipelines, configuring appropriate testing, managing vulnerabilities and threat intelligence, and producing useful compliance evidence can require scarce and expensive specialist expertise. It can also involve months of researching, testing and evaluating different tools.

Phillip is a strong advocate for practical, developer-friendly cybersecurity. He believes effective application security should not only support compliance but also help engineering teams identify and respond to vulnerabilities sooner, particularly as AI-assisted software development continues to grow.

Our Values

Ethics

Purpose-driven – We use cybersecurity to help protect organisations, customers and the wider community.
Protective – We work to reduce the likelihood and impact of security failures.
Responsible – We are clear about what technology can automate and where human judgement remains essential.
Generous – We share practical knowledge so customers can strengthen their own internal capabilities.

Integrity

Trustworthy – We protect customer information and do what we say we will do.
Inclusive – We work constructively with development, security, operations and compliance teams.
Straightforward – We explain complex security issues in clear and practical language.
Knowledgeable – Our recommendations are grounded in hands-on software engineering and cybersecurity experience.

Hard Work

Reliable – We take ownership of outcomes and remain committed when implementation becomes difficult.
Collaborative – We work closely with customers rather than simply handing over tools or reports.
Insightful – We seek to understand each organisation’s architecture, risks and obligations before recommending a solution.
Professional – We apply disciplined engineering, security and customer-success practices to every engagement.