Research

White papers for the people who carry the risk

One idea runs under all of them: detection is cheap and getting cheaper, and trust is not. Anyone can generate a finding, an alert, or a block. Being able to prove it, and being honest about what you cannot, is the whole job. Problems worth your time, each written for a real reader and mapped to how we approach it.

RedSecurity leaders

Four Hundred Findings, Zero Trust

The verification problem in AI security testing, and what to demand instead.

Read · 6 min →
ShieldAppSec & platform teams

After RASP

Why runtime application defense keeps failing, and what the successor has to do differently.

Read · 6 min →
BlueCISO & IT operations

Your Security Agent Is Now Your Biggest Outage Risk

The availability cost of endpoint security, and the case for a driverless design.

Read · 6 min →
ForgeProduct security & maintainers

Machines Are Finding Zero-Days. Can You Trust Them?

Autonomous bug discovery has arrived. The bottleneck moved from finding to proving.

Read · 6 min →
Red · LLMDevelopers & AppSec

The Untested Surface

You shipped an AI feature last quarter. Who is testing it like an attacker?

Read · 7 min →
ShieldDevelopers & API teams

The Attacks Your WAF Was Never Built to See

Business-logic abuse, broken object access, and the case for learning your app's own normal.

Read · 6 min →
RedDevelopers & DevSecOps

Your AI Assistant Is Writing Your Next Breach

Slopsquatting: when the coding model invents a package name, and an attacker registers it.

Read · 6 min →
Red · ForgeBuyers & security leaders

The Pentest PDF Is a Trust Problem

Why security findings should carry their own proof, and what that changes for buyers.

Read · 6 min →
ShieldAI platform teams

Guardrails Aren't a Security Control

Why AI applications need a learned behavioral envelope at the model boundary, not a keyword filter.

Read · 6 min →
BlueCISO & business

Assume Detection Fails

The recovery backstop for ransomware, and why rollback beats faster alerts.

Read · 6 min →