* Virtually every Microsoft senior developer has been trained on software security
* All shipping code is checked in-house, including some homegrown static analysis tools
* Most shipping products have had line-by-line source code reviews done by at least two different firms (we did some of this work for Vista).
During the Summer of Worms in '03, when Microsoft security lapses were front-page material on CNN, Bill Gates told the press that Microsoft was going to totally overhaul security and code quality. They weren't kidding. Microsoft now outspends everybody on that.
Note: I'm a Mac person.