White papers for the people who carry the risk
One idea runs under all of them: detection is cheap and getting cheaper, and trust is not. Anyone can generate a finding, an alert, or a block. Being able to prove it, and being honest about what you cannot, is the whole job. Problems worth your time, each written for a real reader and mapped to how we approach it.
Four Hundred Findings, Zero Trust
The verification problem in AI security testing, and what to demand instead.
Read · 6 min →After RASP
Why runtime application defense keeps failing, and what the successor has to do differently.
Read · 6 min →Your Security Agent Is Now Your Biggest Outage Risk
The availability cost of endpoint security, and the case for a driverless design.
Read · 6 min →Machines Are Finding Zero-Days. Can You Trust Them?
Autonomous bug discovery has arrived. The bottleneck moved from finding to proving.
Read · 6 min →The Untested Surface
You shipped an AI feature last quarter. Who is testing it like an attacker?
Read · 7 min →The Attacks Your WAF Was Never Built to See
Business-logic abuse, broken object access, and the case for learning your app's own normal.
Read · 6 min →Your AI Assistant Is Writing Your Next Breach
Slopsquatting: when the coding model invents a package name, and an attacker registers it.
Read · 6 min →The Pentest PDF Is a Trust Problem
Why security findings should carry their own proof, and what that changes for buyers.
Read · 6 min →Guardrails Aren't a Security Control
Why AI applications need a learned behavioral envelope at the model boundary, not a keyword filter.
Read · 6 min →Assume Detection Fails
The recovery backstop for ransomware, and why rollback beats faster alerts.
Read · 6 min →Protect an App in Two Minutes
One line of code turns “this app only ever behaves in these ways” into an enforced rule, in any language.
Read · 5 min →Guard the Checkout Your Server Never Sees
A skimmer runs in the browser and steals the card before it reaches your server. No backend tool sees it. Here's the two-minute fix.
Read · 5 min →Put a Learned Boundary Around Your AI Feature
Guardrails are a keyword filter. Your LLM app needs a learned behavioral envelope, installable in two minutes.
Read · 5 min →See Every API You Have, Including the Ones You Forgot
Discovery, sensitivity mapping, and BOLA protection for every endpoint, learned from real traffic in two minutes.
Read · 5 min →You Can't Blocklist What Doesn't Exist Yet
AI generates novel attacks faster than any signature can be written. The only defense that scales is learning what your systems are supposed to do, and refusing the rest.
Read · 14 min →