Notes from the lab.
What we discover in the field, we publish. Methodology, research and practice in AppSec and AI security.
09
Jun 2026
Inside our assessments: SAMM, DSOMM and OWASP GenAI
The three open frameworks behind our maturity diagnostics and how they become a score, gaps and a roadmap your team actually tracks.
5 min read
26
May 2026
The two kinds of weakness in the AI era
The risk that already exists when your team develops with AI, and the risk you create when you put AI in production. Different vectors, both happening now.
8 min read
12
May 2026
Threat Modeling Express: the method we use in our workshops
How to engage engineering and product, map critical assets and leave a two-hour session with threats, controls and a prioritized backlog.
8 min read