Blog
Notes on verifying what you shipped
Vibe coding security, AI-generated code vulnerabilities, exposed API keys in client bundles, Supabase row-level security drift and Stripe Connect reconciliation — written by the team building the checks.
A risk score is an opinion with a number attached
A finding you cannot open and check is a notification. What a security report owes you, and what a score quietly removes.
securityevidence4 min readZero standing access
Two of our three products find real problems before receiving any credential. Why that constraint shapes what we can build, and what it costs in coverage.
trustsecurity5 min readYour CI secret scanner is doing its job
A repository scanner that reports nothing is usually correct. The secret it cannot see does not exist until the build creates it.
securityci4 min readThe failures that never throw
Errors get fixed because errors get noticed. The expensive class of failure is the one where every system involved reports success.
engineeringverification3 min readHow to audit an app that was built with AI
Ten checks for an application you did not read line by line — what to run, what a pass looks like, and what each one does not prove.
aichecklist4 min readSource is the wrong place to look
Your repository is clean and your bundle is not. They are different files, and only one of them is served to your users.
verificationsecurity5 min readOutput outgrew review
For most of software's history, code was written and read at roughly the same rate. That proportion has broken, and the failures it produces are structural rather than careless.
aiengineering7 min readWhat verification infrastructure means
Verification infrastructure checks what a system actually does once it is running, rather than what its source says it should do. Why the category needed a name.
categoryverification5 min readIs vibe coding safe?
Vibe coding is safe to the extent that somebody verifies the result. What that means in practice, and the three checks worth running before anyone else does.
aisecurity5 min readIntroducing Veristria
Why three separate security products share one parent company, and what the thing they have in common actually is.
companyverification4 min read