Secure Software, by Design

Writing

View all posts

Redesigning the RPA Framework database keyword to be secure by design: adding parameterized query support upstream to close a SQL injection class affecting low-code/RPA automations, plus a writeup, an exploit/fix demo, and an OWASP cheatsheet.

Robot FrameworkRPA FrameworkPythonSQL InjectionSecure by Design

A framework-agnostic TypeScript implementation of the W3C Device Bound Session Credentials standard, binding sessions to a device key to blunt cookie and token theft.

TypeScriptHonoRedisJWT

A static-analysis ruleset for Opengrep/Semgrep that surfaces what a codebase actually does: network, database, filesystem, crypto, auth, web, and AI usage, to support visibility, threat modeling, and security testing.

OpengrepSemgrepStatic AnalysisJavaScriptTypeScript

A GitHub composite action that runs Opengrep static analysis in CI with pinned releases and checksum verification, emitting JSON/SARIF for the rest of the pipeline.

GitHub ActionsOpengrepSARIFCI/CD

Services

We help engineering teams ship secure software, combining hands-on application security expertise with the rigorous engineering practices. Engagements range from one-off assessments to embedded, longer-term program work.

Including:
  • Strategy
  • Platform Engineering
  • Product Security Assessments
  • Deep Research

Contact

General inquiries, introductions, and anything that doesn't fit the boxes below.