Disclaimer

Last updated: August 2026

Accuracy and currency

Tooling in this area changes fast. A tool's behaviour, a protocol's specification and a provider's terms can all change between one release and the next, and articles here are not continuously revised. Every article carries a publication date. Treat it as a description of the state of things on that date.

Security content

The security material describes threat models, published research and defensive practice. It is written to help engineers protect systems they are responsible for.

It is general information, not a security assessment of your systems. It does not replace review by someone who knows your architecture, your data and your obligations. Where an article describes an attack, it does so to explain what a control needs to defend against — the intent throughout is defensive.

Research citations

Where this site refers to academic research, standards documents or government advisories, it summarises published findings and does not reproduce them. Summaries can lose nuance. If a finding matters to a decision you are making, read the primary source.

Code and configuration

Examples are illustrative and simplified to make a point. They omit error handling, edge cases and environment-specific detail. Do not deploy them without review and testing.

Independence

No vendor sponsors this site and no coverage is paid for. Opinions about tools are the author's own, formed in practice. The site carries display advertising, which is unrelated to editorial content and has no influence on it.

Personal capacity

This site reflects the author's personal views, not those of any employer, client or other organisation.