Security

Security engineering, defense-in-depth, and the attacker's perspective.

Writing on API security, authorization design, penetration testing, and building systems that resist abuse.

Articles

Security writing.

11 min read

Threat modeling an API before the first endpoint ships

Authorization boundaries, attacker workflows, telemetry, and test cases for secure backend design.

Read article →
Coming soon

Writing authorization tests developers will actually maintain

How to turn policy rules into CI-enforced test suites that catch horizontal and vertical privilege escalation.

Coming soon

A methodology for scoped API penetration testing

Recon, enumeration, access control testing, and structured reporting for a single API surface.