Continuous vulnerability patching
We fix security flaws in the app's own code in the sprint time set aside for upkeep. Routine fixes go out in the maintenance window every two weeks. A flaw serious enough to be a critical incident, or one that needs a zero-day patch (an urgent fix for a weakness attackers may already know about), goes ahead of the window instead.