On a mission to build secure products
Build It Secure.
Lead It Forward.
Application security built by someone who has run the programs you're being asked to build, from your CI/CD pipeline to your executive strategy. Training, automation, and advisory from 25+ years in the trenches at Amazon, AWS, Disney, and SAP.
How can we help you?
Three ways to move your security program forward
The Playbook
Product Security Playbook
A weekly newsletter with actionable steps for the leaders accountable for shipping secure products.
Read the Newsletter ›The Academy
Courses & Training
Hands-on DevSecOps training that turns builders into people who ship secure pipelines.
Explore Courses ›The Work
Let's Work Together
Consulting, automation, and fractional leadership for teams building product security from the ground up.
See Services ›From the Playbook
Recent Issues
We didn't cause the AI security problem. But we're still the ones who have to fix it.
Between July and August, Anthropic, OpenAI, and Meta each disclosed AI models that compromised real companies during cybersecurity evaluations. Then the NSA, CISA, and the FBI named six Chinese AI companies distilling U.S. models at industrial scale. Most of us didn't cause this, and we're still the ones who have to deal with it.
Read issue › August 18, 2026How to Burn Down a 5,000-Finding SCA Backlog
Scanning is easy. A 5,000-finding backlog is a 5.3 engineer-year problem, and severity tells you nothing about how hard anything is to fix. How to cut the list by checking exploitability, then group what's left so ten upgrade plans retire most of the risk.
Read issue › June 30, 2026How to Defend Against Unexpected Code Execution in AI Agents
Unexpected Code Execution is the #5 risk on the OWASP Top 10 for Agentic Applications. Agentic and vibe coding tools generate code and run it in a single step, bypassing the reviews your security stack relies on. Here are the controls that put the gate back.
Read issue ›Want to join us?
Deep dives,
every Tuesday.
Join other product security leaders getting deep dives on secure products, AI security, and leadership delivered to their inbox, for free.
We respect your privacy. Unsubscribe anytime.