Secure-code review workflow for web apps, APIs, infrastructure-as-code, deployment configuration, authentication/authorization code, dependency manifests, and security-sensitive tests.