Research

White papers for the people who carry the risk

One idea runs under all of them: detection is cheap and getting cheaper, and trust is not. Anyone can generate a finding, an alert, or a block. Being able to prove it, and being honest about what you cannot, is the whole job. Problems worth your time, each written for a real reader and mapped to how we approach it.

RedSecurity leaders

Four Hundred Findings, Zero Trust

The verification problem in AI security testing, and what to demand instead.

Read · 6 min →
ShieldAppSec & platform teams

After RASP

Why runtime application defense keeps failing, and what the successor has to do differently.

Read · 6 min →
BlueCISO & IT operations

Your Security Agent Is Now Your Biggest Outage Risk

The availability cost of endpoint security, and the case for a driverless design.

Read · 6 min →
ForgeProduct security & maintainers

Machines Are Finding Zero-Days. Can You Trust Them?

Autonomous bug discovery has arrived. The bottleneck moved from finding to proving.

Read · 6 min →
Red · LLMDevelopers & AppSec

The Untested Surface

You shipped an AI feature last quarter. Who is testing it like an attacker?

Read · 7 min →
ShieldDevelopers & API teams

The Attacks Your WAF Was Never Built to See

Business-logic abuse, broken object access, and the case for learning your app's own normal.

Read · 6 min →
RedDevelopers & DevSecOps

Your AI Assistant Is Writing Your Next Breach

Slopsquatting: when the coding model invents a package name, and an attacker registers it.

Read · 6 min →
Red · ForgeBuyers & security leaders

The Pentest PDF Is a Trust Problem

Why security findings should carry their own proof, and what that changes for buyers.

Read · 6 min →
ShieldAI platform teams

Guardrails Aren't a Security Control

Why AI applications need a learned behavioral envelope at the model boundary, not a keyword filter.

Read · 6 min →
BlueCISO & business

Assume Detection Fails

The recovery backstop for ransomware, and why rollback beats faster alerts.

Read · 6 min →
Shield · Get startedDevelopers & AppSec

Protect an App in Two Minutes

One line of code turns “this app only ever behaves in these ways” into an enforced rule, in any language.

Read · 5 min →
Shield · BrowserE-commerce & payments

Guard the Checkout Your Server Never Sees

A skimmer runs in the browser and steals the card before it reaches your server. No backend tool sees it. Here's the two-minute fix.

Read · 5 min →
Shield · LLMAI platform teams

Put a Learned Boundary Around Your AI Feature

Guardrails are a keyword filter. Your LLM app needs a learned behavioral envelope, installable in two minutes.

Read · 5 min →
Shield · APIAPI & platform teams

See Every API You Have, Including the Ones You Forgot

Discovery, sensitivity mapping, and BOLA protection for every endpoint, learned from real traffic in two minutes.

Read · 5 min →
Positive SecurityFinancial institutions & security leaders

You Can't Blocklist What Doesn't Exist Yet

AI generates novel attacks faster than any signature can be written. The only defense that scales is learning what your systems are supposed to do, and refusing the rest.

Read · 14 min →