Featured Posts

  • Sales enablement
  • Risk & compliance

The SOC2 starting seven

  • icon Mar 12, 2020
  • icon 17 minutes read
  • icon 3603
So, you plan to sell your startup’s product to big companies one day. Congratu-dolences! Really, that’s probably the only reason you should care about this article. If …
Read more

All blog posts

  • Architecture
  • Cloud Security

OIDC workload identity on AWS

  • icon Nov 04, 2025
  • icon 11 minutes read
  • icon 2235
Introduction # We’re big fans of Tailscale. It’s fast, secure, and the developer experience doesn’t make you want to throw your laptop out the window. It makes my cryptographer heart sing, too: it’s based on WireGuard, which …
Read more
  • Infrastructure security

ECS on EC2: Covering Gaps in IMDS Hardening

  • icon Oct 02, 2025
  • icon 10 minutes read
  • icon 1945
Introduction # AWS ECS is a widely-adopted service across industries. To illustrate the scale and ubiquity of this service, over 2.4 billion Amazon Elastic Container Service tasks are launched every week (source) and over 65% of all new AWS …
Read more
  • Infrastructure security
  • Tooling

Introducing Replik8s, a Modern Security Tool for Kubernetes

  • icon Sep 22, 2025
  • icon 3 minutes read
  • icon 524
Introduction # Security tools are often designed to highlight specific issues by consuming APIs and applying predefined logic. Each tool implements its own data structures, storage formats, and evaluation logic. While effective in narrow contexts, …
Read more
  • Sales enablement
  • Risk & compliance

Privacy for the newly appointed (and already exasperated) DPO

  • icon Jun 27, 2025
  • icon 7 minutes read
  • icon 1414
Every other week, regulators around the world bombard their constituents with new data protection laws and acronyms. As the person who was just voluntold you’re now responsible for privacy at your startup, in addition to all your other duties and …
Read more