Platform teams in 2026 face the same problem that has dogged DevSecOps since the term emerged. Scans pass. Builds stay green. Yet incidents still trace back to decisions made in the wrong place at the wrong time. Cloudaware’s May 2026 update on its reference architecture lays out six layers that have held up under real scale, along with three approaches that collapse when volume rises. The model focuses on decision points rather than tool lists. Valentin Kel, DevSecOps practice lead at Cloudaware, reviewed the piece. It includes whiteboard diagrams and an Azure mapping for teams that need a concrete starting point. The core idea is straightforward. Security decisions must sit where the risk category can be handled cheapest and with clearest ownership. Code defects, supply-chain issues, environment-specific exposure, and runtime drift each surface at different moments. Treating them identically breaks automation and buries evidence. Early layers handle prevention.…