Blog
Notizen zu Security-Research, KI-gestützten Pentests und den technischen Entscheidungen hinter den Projekten, die ich baue.
- Juni 2026 · 6 Min. Lesezeit
We Built an AI Teammate That Takes the Grind Out of Security Questionnaires
A small security team was spending whole days answering the security questionnaires customers and prospects send by hand. So we built an AI assistant. My piece was the engineering layer that makes it trustworthy: live sources, draft-only guardrails, a reusable skill, and an audit trail on every correction.
AI·Security Compliance·Security Questionnaires·GRCLesen - Juni 2026 · 11 Min. Lesezeit
Today I Learned: Genuinely Capable AI Now Runs on My Laptop
I ran Gemma 4 QAT locally on a MacBook Pro M5 Pro: 12B and 26B fully on the GPU, 31B partial. What clicked about local AI for security and compliance, and the risks it doesn't solve.
Local AI·Gemma 4·GDPR·LLM SecurityLesen - April 2026 · 18 Min. Lesezeit
I Spent $8 to Mass-Pentest My SaaS. A Human Would Have Cost $15,000.
1,138 adversarial tests, 40+ live HTTP attacks, and 10 real vulnerabilities found and fixed across two projects.
Claude Code·Burp MCP·PentestingLesen - April 2026 · 25 Min. Lesezeit
Everyone Vibe-Codes. Nobody Vibe-Engineers.
A complete engineering tour from browser to database and back. Real production standards. How the industry does it. How you can too.
Architecture·Security·DevOps·StartupsLesen - April 2026 · 10 Min. Lesezeit
Why I Wired Observability Before Writing a Single Feature
Building a compliance SaaS solo. The first night wasn't features. It was measurement infrastructure. EU-first, privacy-by-design.
Observability·GDPR·Solo FounderLesen