Closer to CI/CT expansion than DevSecOps
DevSafetyOps adds ISO 26262 and IEC 62279 verification, quality metrics, and evidence management to the CI/CT structure already familiar to automotive engineering teams.
Consulting
Overview
Concept
DevSafetyOps adds ISO 26262 and IEC 62279 verification, quality metrics, and evidence management to the CI/CT structure already familiar to automotive engineering teams.
In-vehicle control software and cloud-to-car systems should be treated together, including OTA, diagnostics, data processing, monitoring, and backend operations.
Build scripts, test settings, containers, virtual ECUs, and runner environments should be managed as configurations so production-era environments can be restored years later.
Operating Model
Run static analysis, coding-rule checks, test techniques, coverage, and source-quality metrics continuously during development.
Add vulnerability checks, open-source composition, SBOM analysis, and quality gates before merge and release.
Connect requirements, change requests, code, build results, tests, coverage, and evidence as a traceable pipeline.
Architecture
VMs, containers, compilers, and test runners can be recreated at a specific point in time, even years after mass production.
JIRA or Redmine, Git, and CI/CT are connected so each feature or defect change is tied to build and verification results.
Virtualized environments reduce dependency on specific PCs or servers and make verification continuity more resilient.
Delivery Record
We have implemented virtualized software build and verification environments for aerospace organizations including KARI and KAI, with configuration-managed operation.
We have built virtualized build and verification environments and repeatable CI/CT operating models for automotive organizations including PopcornSAR.
We have applied virtualized SW build and verification environments in railway organizations including ANTZ, connecting directly to IEC 62279-oriented development.
We have trained Hyundai Motor Group, Lotte Innovate, Asiana IDT, and TTA on CI/CT and configuration-based operating models.
Expertise
We design requirements, changes, builds, tests, evidence, and configuration management so the environment of a specific point in time can be restored.
Static analysis, test techniques, coverage, and code-quality metrics are placed inside the development flow with evidence structures.
We connect Jenkins with analysis, testing, coverage, quality metrics, and vulnerability-management tools to create CI/CT structures that operate in practice.