Security for apps that were mostly generated
Long form on the parts that are genuinely hard: proving what you have checked, reading regulation written for companies a hundred times your size, and answering the security question without either overclaiming or freezing.
- Method6 September 20267 min read
Why VibeLock will never give you a security score
Something you show an investor has to survive being questioned. That rules out asking a model to grade you, and followed far enough it rules out any number of our own invention.
Read - Practice23 June 20269 min read
What AI coding tools actually get wrong, and what they do not
The security failures in AI generated applications are not exotic. They are a small, predictable set, and knowing which ones lets you check the right twenty things instead of the wrong two hundred.
Read - Compliance19 May 20268 min read
The EU AI Act when you are three people and an app
Most of the writing about the AI Act is addressed to organisations with a compliance function. Here is the part that applies when you do not have one, and the part that probably does not apply to you at all.
Read - Practice28 April 20266 min read
The security question in the fundraise, and how it actually goes
Nobody is expecting a seed stage company to have SOC 2. What they are testing is whether you can tell the difference between what you have done and what you have not.
Read