Insights
Security
Penetration testing, application and cloud security, AI/LLM red teaming and compliance — practical, from engineers who ship.
Security
Security ·
SealedRun: Tamper-Evident Audit Trails for AI Agents
Agent traces stored in your own database are claims, not evidence: whoever runs the store can edit it. SealedRun, an early-stage open-source recorder, signs every agent step into a hash chain that an outsider can verify offline. Here is how it works, what it proves, and how we run it for our own agents.
9 min read
Security ·
OWASP Top 10 for LLM applications, explained for people who ship them
The 2025 list names ten ways an LLM app gets attacked. Here is what each one looks like in a real chatbot, RAG system or agent — and the fix we apply in production.
4 min read
Security ·
Penetration test or vulnerability scan: which one to order, and when
Customers ask for a "pentest" and often mean a scan; vendors sell a scan and call it a pentest. What each really is, what it costs in time, and a schedule that works for a product team.
4 min read
Security ·
Securing AI agents in production: seven controls we never skip
An agent that can read your CRM and send emails is an employee with no judgement and infinite patience for a well-written attack. The controls that let us connect agents to real systems without losing sleep.
4 min read