Secure software development and review: OWASP Top 10 (2025) and ASVS 5.0 as review frameworks, STRIDE/data-flow threat modelling, secure SDLC practices, input/output handling, secrets and cryptography hygiene, dependency and supply-chain security — plus engineering-obligation references for NIS2, GDPR (privacy by design) and the EU AI Act. Use for ANY work involving application security, security reviews/audits, threat models, OWASP/ASVS, vulnerability remediation, secrets management, supply-chain risk, or developer-facing NIS2/GDPR/AI-Act compliance questions.