Security engineering,
leadership, and practice.

Notes on building security teams, automating compliance, and the architecture and organizational calls that decide whether a security program works.

AWS Credential Isolation for Local AI Agents

If you run local agents, you need to make tough choices between autonomy and safety. Setting dangerously-skip-permissions while sword fighting on desk chairs and letting the tokens burn bright is...

Read →

TrailTool: CloudTrail for AI Agents

Update: TrailTool 1.0 is out, with an identity-first session model and a lot more. See TrailTool 1.0: Identity-First Sessions for CloudTrail for what changed.

Read →

GraphGRC v2: SOC 2 Compliance in GitHub

Commercial GRC tools can cost $12K+/year and lock your compliance docs in proprietary systems. GraphGRC v2 gives you SOC 2 documentation in GitHub - pre-written controls, policies, and processes in...

Read →

Backyard APT: A Raccoon Story

Raccoons are both advanced and persistent threats. After one attacked my chihuahua Jolene, I declared war on my backyard invaders. Through ultrasonic deterrents, motion-activated sprinklers, and wacky inflatable air dancers,...

Read →

Data Retention is Two Different Problems

Data retention covers two different problems - preservation (minimum time you must keep archival data) and deletion (maximum time you can keep personal data). They require opposite technical approaches -...

Read →

Refocusing Vendor Security on Risk Reduction

Modern software companies use a lot of software services. Traditional security teams address third-party risk through certifications and questionnaires, but there's an opportunity to actually reduce risk by collaborating with...

Read →