Blog

Field notes.

What we learn breaking AI products.

APIs

Multi-tenant APIs: five common mistakes

IDs in URLs, trusted headers, unchecked bulk endpoints.

Coming soon
Process

Your first pentest: how to prepare

Test accounts, a signed scope and who to call when we find something.

Coming soon
Process

Grey box or black box?

What changes when we start with credentials, and when starting from zero is worth it.

Coming soon
LLM security

RAG and access control

Vector stores don't know your roles. Make them.

Coming soon
APIs

Rate limits are security

Why we always test them, and what an LLM endpoint without one costs.

Coming soon
Process

Reading a pentest report

What the severities mean. What to fix this week, and what can wait.

Coming soon