Blog

Field notes from the forge

Technical insights, security research, and lessons learned from 20+ years of building and securing systems at scale.

Jan 28, 2026

The Real Cost of Retrofitting Security

A dollar spent on security at the design phase saves a hundred in breach response. We break down the actual numbers from three engagements.

Read more →
Jan 14, 2026

Prompt Injection Is a Supply Chain Problem

Why securing LLM applications requires the same rigor as dependency management — and the playbooks most teams are missing.

Read more →
Dec 19, 2025

Zero-Trust at 500M Users: Lessons from Scale

What we learned implementing zero-trust network architecture for a platform serving half a billion monthly active users across 8 regions.

Read more →
Dec 3, 2025

SOC 2 Doesn't Have to Be Painful

How we architect compliance into systems from sprint one — and why retro-fitting it costs 10x more than building it in.

Read more →
Nov 18, 2025

Risk vs. Reward: A Framework for Security Investment

Not every vulnerability is worth fixing today. Here's the framework we use to help leadership make informed decisions about where to invest.

Read more →
Nov 2, 2025

Migrating to GCP Without Breaking Compliance

A technical deep-dive into maintaining SOC 2 Type 2 and NYS DFS Part 500 compliance during a full AWS-to-GCP cloud migration.

Read more →
Ready to Start

Let's build it secure from the start.

Whether you're designing a new platform, scaling an existing one, or navigating a compliance milestone — we'll meet you where you are.