Imagine two mission-critical systems exchanging sensitive data, when either system, or the network between them, could be compromised. We’ll build the integration architecture step by step, introducing trust boundaries, identities, access control, data minimisation, encryption, and other security controls that limit blast radius. We’ll show how layered architectural decisions can keep systems secure and resilient even when individual controls fail.
Anastasiia Voitova
(Head of security engineering at Cossack Labs),This talk will explore what software engineering looks like when a product becomes part of a national digital infrastructure. Millions of citizens, government registries, critical infrastructure, personal data, dozens of integrations, and strict security requirements fundamentally change the rules of software development. Things that work well in the private sector may require a completely different approach in GovTech. We will follow the journey from idea to production, covering the principles behind building a SuperApp, product discovery, the specifics of the SDLC, on-premise and cloud infrastructure, cybersecurity, and information security. We will also take a closer look at AI in GovTech — from collecting and preparing data for proprietary models to developing AI components and integrating them into government digital products. The talk will show how to balance real-world constraints with modern engineering practices while maintaining the ability to build and continuously evolve digital services at national scale.
Oleksandr Savchenko
(CTO at Ministry of Digital Transformation),Nowadays, everyone is creating AI Assistants to help us in our day-to-day activities and "vibe coding" nice and shiny demo apps. However, when you try to bring AI Assistants to life in production—especially to be used by the citizens of a Gov Portal—you realize that creating the AI Agent itself is only 10% of the effort required. The other 90% is spent on satisfying cross-cutting concerns and different stakeholder concerns. This talk will be based on my own experience of putting citizen AI Assistants for a Gov Portal (built on top of an AI Agentic Platform) into production. I'll talk about the challenges we faced, concerns we received from different groups of stakeholders, important NFRs and quality attributes of the solution, and possible solutions for these challenges. This talk will give useful tips, provide a wider view on real-world challenges, and improve critical thinking. This talk will be interesting for diff Roles to get a wider view on real world challenges and to improve critical thinking. Amongst other topics I want to talk about (not in order for now): - Naive implementation of Chatbot -vs- scalable and mature implementation - Benefits and drawbacks of using AI Agentic Platform -vs- custom implementation - Choice of Public LLM vs Private LLM - Performance and quality challenges - Infrastructure - Costs - Error handling - UI/UX - Guardrails and protection against misuse and DDOS attacks - Observability - Multilingual support - Testing and evaluation framework - PII data handling - and more...
Oleg Tsal-Tsalko
(CTO at EPAM),Implementing AI into a government service with 23+ million users is a journey of continuous product discoveries and challenges. In this talk, I will share the real-world experience of how the "Diia" ecosystem is transitioning from a classic Digital State (where users search for the required services themselves) to an Agentic State (where AI proactively fulfills the user's intent). What we will cover: - Product Discovery and Paradigm Shift: The transition from Digital State to Agentic State. Why traditional interfaces have reached their limits and how we validated the need for proactive AI solutions. - AI in Support as the First Big Step: How we automated 90% of requests without a drop in quality (CSAT). Soft AI UX: why people struggle with prompting and how we guide them using hybrid interfaces. - The Upskill Case and Team Transformation: We didn't fire a single operator. How we built internal AI tools for the team, turning yesterday's support agents into AI trainers. - Deep Dive into Diia.AI on the Portal: The launch of the world's first agentic service at the government level. How our RAG architecture works, how we architecturally protect personal data (PII) from entering the LLM, and how we repel jailbreak attempts.
Denys Korovin
(AI Product Manager at WINWIN AI Center of Excellence (Ministry of Digital Transformation of Ukraine)),In technology companies, AI is already going beyond the trend and influencing products, engineering, and daily business processes. Along with opportunities come challenges: working with sensitive data, security requirements, and the complexity of integration into existing systems. In such conditions, it is important to understand where AI really creates value and where it just adds noise. During the discussion, participants share their practical experience: how they implement AI in their products, adapt engineering processes, and restructure operations for new tools. This is a conversation about real pain points, opportunities, and solutions that help teams move forward.
Vadym Vlasenko
(Preply, Senior Engineering Director),Denys Rumiantsev
(CTO Hily в appflame),Oleksandr Tarasenko
(CTO at RozetkaPay),Oleksandr Chumak
(CTO, Uklon),A discussion with representatives of high-risk systems about why security architecture should be incorporated at the design and development stage, rather than added after release into production. We will talk about the risks of delayed implementation of controls, common security illusions, and practical approaches to integrating security practices into the work of product teams.
Anastasiia Voitova
(Head of security engineering at Cossack Labs),Yuriy Fedorenko
(Engineering manager, MacPaw),Artem Martynenko
(Center of innovations),Oleh Shemetov
(CISO Міноборони),Vitaly Balashov
(Deputy Minister, Ministry of Digital Transformation of Ukraine),
Serhii Vasylenko
(Software Engineer, Grammarly),The talk focuses on developing and integrating automation tools to enhance Supply Chain security. It addresses reproducible security practices with tools like Renovate and Wiz, as well as GitLab and JFrog Artifactory, to enforce consistent security scans seamlessly within existing workflows.
Serhii Vasylenko
(Software Engineer, Grammarly),Do machines hallucinate insecure code? In the blink of an eye we jumped on the AI bandwagon and pivoted from AI skepticism to AI adoption, but what did we trade off exactly? Writing secure code is tougher than it seems and we humans are getting it wrong time and time again. Even highly popular open-source software projects are repeatedly found vulnerable. So how does ChatGPT or GitHub Copilot live up to standards of secure software? developers have already embraced AI for augmented software development but let's challenge those AI tools you've come to rely on day-to-day and see how capable they are in producing secure software.
Liran Tal
(Snyk),
Marco De Sanctis
(Mondra),