May 14, 2026
08:30am - 3:00pm
Hyatt Regency San Francisco

San Francisco Secure Software and AppSec Summit 2026

Advance your development process with cutting-edge security practices. Join us for the inaugural San Francisco edition of the AppSec and DevSecOps Summit, bringing together developers, security leaders, and innovators to strengthen application security from code to cloud.

San Francisco Secure Software and AppSec Summit 2026
Fortify your software development lifecycle.

This summit unites developers, security experts, and industry leaders to seamlessly embed security into every stage of the development process.

Discover best practices for shifting left, automating security, and managing open-source risks. Explore how to enhance DevSecOps adoption, secure containers and microservices, and weigh in on the debate: automation vs. manual testing. Participate in interactive sessions, real-world case studies, and dynamic panel discussions to stay ahead of evolving AppSec trends.

Key Themes:
  • Integrating Security into the Software Development Lifecycle
  • Shift Left Strategies
  • Application Breach Response
  • Automating Security Processes
  • Managing Open Source Risks
  • Improving DevSecOps Adoption
  • Container and Microservices Security
  • Automation vs. Manual Testing: What Works Best
Speakers & Full Agenda Announced Soon!

Our speaker lineup will be revealed in February 2026.

Register now to secure your spot and get notified when the full program launches.

Our Speakers

Kavitha Venkataswamy

Kavitha Venkataswamy

Product Security Director
Siva Inguva

Siva Inguva

Head of Security - SaaS
Balachandra Shanabhag

Balachandra Shanabhag

Product Security Lead
Cole Cornford

Cole Cornford

Chief Executive Officer
Register Now

Register Now

To receive speaker and program updates and secure your seat!

Agenda

8:30am
Registration Opens, Breakfast, Barista Coffee & Networking
No items found.
9:30am
Securing Autonomous AI Agents: The New Attack Surface No One Is Ready For

AI has shifted from assistants that make suggestions to autonomous agents that can read files, execute commands, call APIs, and modify systems on their own. That change expands the attack surface from prompt injection to full system compromise, lateral movement between agents, and persistent access through memory and tooling. 

This session explores how autonomous agents are reshaping the threat model, what early adopters are discovering in practice, and the questions AppSec teams must confront as AI systems gain more autonomy and more potential for harm.

The speaker will cover:

  • New risks from code-executing prompt injection to agent-to-agent lateral movement
  • How teams are designing permissions, audit trails, sandboxing, and monitoring agent behavior
  • Examples of agents being manipulated to exfiltrate data or modify configurations
  • The security shifts required to safely deploy autonomous agents in the next year

No items found.
9:50am
Panel: The Evolving Supply Chain Risk Landscape: SBOM Gaps, AI Model Leakage & Dependency Sprawl

Software supply chain risks are growing more complex as modern applications rely on deep dependency trees, AI-generated components, and tools that introduce new layers of abstraction. 

Even with SBOMs and automated scanning, many teams struggle to catch issues hidden in transitive packages, dormant services, and emerging AI model leakage paths. As development accelerates, the challenge is no longer visibility at build time, it’s maintaining reliable, end-to-end awareness.

 This panel explores the supply chain risks that are hardest to surface and how leading teams are adapting their practices to keep pace with a rapidly shifting ecosystem.

The panel will cover:

  • Where SBOMs provide value and where they still fall short
  • How AI models, agent tooling, and opaque dependencies introduce new exposure points
  • What transitive, dormant, and abandoned dependencies mean for real-world risk
  • Practical approaches for regaining control of complex dependency chains

No items found.
10:20am
Morning Tea & Networking
No items found.
10:50am
Interactive Audience Activity: Live Simulation

In this innovative session, attendees will be faced with a series of scenarios that they may face in their roles. Attendees will discuss the possible courses of action with their peers to consider the ramifications of each option before logging their own course of action.

Results will be tallied and analysed by our session facilitator and results will impact the way the group moves through the activity.

Will we collectively choose the right course of action?

No items found.
11:10am
How we Solve Session 1
No items found.
11:25am
How we Solve Session 2
No items found.
11:40am
Panel: Security vs Velocity: When to Say Yes to Risk (and How to Track What You Said Yes To)

Modern engineering teams move fast, and AppSec teams are constantly negotiating when to block, when to slow down, and when to accept risk to keep delivery on track. As exceptions, waivers, and temporary approvals become part of everyday workflows, many organizations struggle to understand what risks they’ve accepted, why they accepted them, and whether those decisions are still defensible months later. 

This panel explores how high-performing teams balance speed with security, how they document and monitor accepted risk, and the frameworks that keep fast-moving environments accountable.

The panel will cover:

  • How teams decide when risk acceptance is justified and when it isn’t
  • Practical approaches to tracking exceptions, waivers, and approvals over time
  • Techniques for documenting context so decisions remain defensible later
  • How AppSec and engineering collaborate to keep velocity without losing control

Siva Inguva
Head of Security - SaaS, PTC
Kavitha Venkataswamy
Product Security Director, Capital One
12:40pm
Roundtable Discussions

Select a topic of discussion and engage in an interactive roundtable discussion with a group of your like-minded peers.

No items found.
1:00pm
Lunch & Networking
No items found.
2:00pm
Keynote: Everything Is an API Now. So Why Are They Still the #1 Breach Vector?

APIs power every modern product, yet organizations continue to face the same breach patterns year after year: over-permissioned data exposure, zombie endpoints left running long after teams move on, and orphaned microservices no one remembers owning. As architectures become more distributed and engineering velocity accelerates, the real challenge isn’t building APIs, it’s controlling their sprawl. 

This session explores why API security has fallen behind, why traditional controls haven’t kept pace, and what needs to change for teams to finally get ahead of the problem.

The speaker will cover:

  • Why API sprawl creates persistent security blind spots
  • How over-permissioned data, zombie endpoints, and orphaned services become breach paths
  • What leading teams are doing to regain visibility and ownership
  • Practical steps to modernize API security in the next year

No items found.
2:30pm
Think Tank: How AppSec Should Really Operate: Live Debate With the Audience

AppSec teams sit at the center of fast-moving engineering organizations, yet there’s still no consensus on how they should be structured, what they should own, or how much authority they should have to slow things down. 

This interactive session puts those debates on the screen literally. The audience votes live on five core questions covering team design, ownership boundaries, blocking power, developer experience, and how AI is reshaping the AppSec operating model. We explore the results, debate the trade-offs, then vote again to see if perspectives shift in real time.

This session will cover:

  • How structure and ownership shape AppSec’s influence
  • When blocking authority helps or harms engineering velocity
  • How AI is forcing teams to rethink traditional operating models
  • What leading organizations are learning about building developer-first AppSec

Balachandra Shanabhag
Product Security Lead, Cerebras
3:00pm
Event Closed
No items found.

Past Speaker Highlights

No items found.

Who Attends?

Chief Technology Officer

Chief Information Security Officer

Chief Information Officer

Head of Application Security

Head of DevOps

Head of DevSecOps

Head of Cybersecurity

VP Engineering

Product Security Director

DevOps Director

DevOps Engineer

Developer Experience Manager

Release and Environment Manager

Platform Engineering Director

Software Engineering Manager

Cybersecurity Engineering Director

API Security Manager

Testing Manager

Man in gray blazer holding a laptop and talking to another man wearing a black jacket with a conference badge, surrounded by other attendees with badges at an indoor event.Audience seated in a conference room watching a speaker present slides about winning fantastic prizes on large screens.Crowd of people networking indoors at a conference or event with informational booths in the background.Audience attentively listening to a speaker in a conference room with round tables and water pitchers.

Attendee Testimonials

No items found.
No items found.
No items found.
No items found.

Our event sponsors

No items found.
For sponsorship opportunities, please get in touch with Danny Perry, danny@clutchgroup.co

Past Sponsors

Event Location

Hyatt Regency San Francisco

5 Embarcadero Ctr, San Francisco, CA 94111, United States
San Francisco Secure Software and AppSec Summit 2026

Frequently Asked Questions

No items found.

Get In Touch

Contact our event team for any enquiry

Danny Perry

Director of Sales
For sponsorship opportunities.
danny@clutchgroup.co

Lili Munar

Director of Client Relations
For guest and attendee enquiries.
lilibeth@clutchgroup.co

Steph Tolmie

Director of Conference Production
For speaking opportunities & content enquiries.
stephanie@clutchevents.co

Taylor Stanyon

Director of Operations
For event-related enquiries.
taylor@clutchgroup.co