Home / Blog
The blog
Notes from building it.
Written by the people building the product, about the parts of it we have opinions on. No guest posts, no keyword pages, nothing we cannot show you in the console.
Posts
Three so far
The blog is new. These are the three arguments we make most often, written down properly so we can stop making them badly on calls.
Who can see what: the test your scanner cannot run
A scanner has one login, so there is one question it can never ask. What the matrix is, why it needs five accounts, and what a single leaked square costs.
Why we publish what we miss
Every tool in this space leads with a big number. We could produce one this week and it would mean nothing. What we are measuring instead, and when it lands.
What belongs in a finding, and what does not
Request, response, screenshot, line of code. Anything missing one of those is a suspicion, and suspicions are the reason nobody reads the second report.
What we will write about
Five things worth writing down
Three of these have a post today. The rest are empty, and an empty category is better than a filler post with our name on it.
Findings and teardowns
The classes of bug we keep finding, taken apart: what the code did, what the server did, and why the two disagreed. Our own work and public research, never a customer's application without their written say-so.
Building Cyberlop
Decisions made in the open. What we shipped, what slipped, what we tore out after two weeks, and the trade-offs behind a platform built by five people and some interns.
The benchmark
Method, results and arguments about method. The first run publishes 3 November with the misses in it, and the second on 2 March with the two diffed.
For MSSPs
Running this for other people: white-label reports, the multi-client console landing 27 November, and the commercial shape of reselling testing you did not have to staff. The partner programme →
Playbooks
Practical things a security or engineering lead can use the same afternoon, whether or not they ever buy from us. How to read a finding, how to scope a pilot, what to ask a testing vendor.
Honesty, as a standing rule
We publish the misses, we report a slipped date the week it slips, and we do not invent numbers, customers or quotes to fill a post. What we have not proved yet →
Reading about it is not the same as running it.
Those three posts are the arguments we make most often. If one of them is the claim you are unsure about, we would rather demonstrate it than write a fourth post.
Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.