What the buyer is really asking
Do you think about attackers before you build, or only after? A short, honest description of when design review happens is better than claiming a formal methodology you do not use.
Other ways buyers ask it
Every one of these wants the same answer:
- “Do you perform threat modeling?”
- “How is security considered during design?”
- “What threat modeling methodology do you use?”
Evidence to have ready
- Design review templates or records
- An example threat model, if one exists
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.