Briefly address security without deep diving unless asked. Mention: authentication at API gateway, authorization checks, input validation, encryption at rest and in transit.
For sensitive systems (payments, health), proactively discuss: PCI compliance, HIPAA, audit logging. Shows awareness without derailing the conversation.