Threat modeling while the design is still on paper, not after launch.
Security is a design constraint, not a final audit. We model attack surfaces before a line of code is written and bring in independent penetration testing for regulated or high-sensitivity workloads.