Writing
Notes on security research, AI-assisted pentesting, and the engineering decisions behind the projects I build.
- June 2026 · 6 min read
We Built an AI Teammate That Takes the Grind Out of Security Questionnaires
A small security team was spending whole days answering the security questionnaires customers and prospects send by hand. So we built an AI assistant. My piece was the engineering layer that makes it trustworthy: live sources, draft-only guardrails, a reusable skill, and an audit trail on every correction.
AI·Security Compliance·Security Questionnaires·GRCRead - June 2026 · 11 min read
Today I Learned: Genuinely Capable AI Now Runs on My Laptop
I ran Gemma 4 QAT locally on a MacBook Pro M5 Pro: 12B and 26B fully on the GPU, 31B partial. What clicked about local AI for security and compliance, and the risks it doesn't solve.
Local AI·Gemma 4·GDPR·LLM SecurityRead - April 2026 · 18 min read
I Spent $8 to Mass-Pentest My SaaS. A Human Would Have Cost $15,000.
1,138 adversarial tests, 40+ live HTTP attacks, and 10 real vulnerabilities found and fixed across two projects.
Claude Code·Burp MCP·PentestingRead - April 2026 · 25 min read
Everyone Vibe-Codes. Nobody Vibe-Engineers.
A complete engineering tour from browser to database and back. Real production standards. How the industry does it. How you can too.
Architecture·Security·DevOps·StartupsRead - April 2026 · 10 min read
Why I Wired Observability Before Writing a Single Feature
Building a compliance SaaS solo. The first night wasn't features. It was measurement infrastructure. EU-first, privacy-by-design.
Observability·GDPR·Solo FounderRead