The questions behind the phrase
- Will developers get useful feedback fast enough to act while they are still coding?
- Does the operating model require sending full source code away just to get the first security review?
- Can the team preserve privacy and speed without losing shared visibility later?