Platform

Platform overview How it works Authorization testing Evidence & reports Private scanning Integrations

Solutions

Security agencies Product teams Regulated industries Partner programme

Learn

Blog Knowledge hub Compare

Resources

Pricing Documentation FAQ Security & data What we haven’t proved

Company

About Contact Careers Sign in to the platform Start a $199 pilot

Home / Blog

The blog

Notes from building it.

Written by the people building the product, about the parts of it we have opinions on. No guest posts, no keyword pages, nothing we cannot show you in the console.

Posts

Three so far

The blog is new. These are the three arguments we make most often, written down properly so we can stop making them badly on calls.

Findings and teardowns

Who can see what: the test your scanner cannot run

A scanner has one login, so there is one question it can never ask. What the matrix is, why it needs five accounts, and what a single leaked square costs.

Read it →

The benchmark

Why we publish what we miss

Every tool in this space leads with a big number. We could produce one this week and it would mean nothing. What we are measuring instead, and when it lands.

Read it →

Playbooks

What belongs in a finding, and what does not

Request, response, screenshot, line of code. Anything missing one of those is a suspicion, and suspicions are the reason nobody reads the second report.

Read it →

What we will write about

Five things worth writing down

Three of these have a post today. The rest are empty, and an empty category is better than a filler post with our name on it.

Findings and teardowns

The classes of bug we keep finding, taken apart: what the code did, what the server did, and why the two disagreed. Our own work and public research, never a customer's application without their written say-so.

Building Cyberlop

Decisions made in the open. What we shipped, what slipped, what we tore out after two weeks, and the trade-offs behind a platform built by five people and some interns.

The benchmark

Method, results and arguments about method. The first run publishes 3 November with the misses in it, and the second on 2 March with the two diffed.

For MSSPs

Running this for other people: white-label reports, the multi-client console landing 27 November, and the commercial shape of reselling testing you did not have to staff. The partner programme →

Playbooks

Practical things a security or engineering lead can use the same afternoon, whether or not they ever buy from us. How to read a finding, how to scope a pilot, what to ask a testing vendor.

Honesty, as a standing rule

We publish the misses, we report a slipped date the week it slips, and we do not invent numbers, customers or quotes to fill a post. What we have not proved yet →

Reading about it is not the same as running it.

Those three posts are the arguments we make most often. If one of them is the claim you are unsure about, we would rather demonstrate it than write a fourth post.

Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.