Field notes
- 2026-05-09
Why we ship validated findings only
A sandboxed validator is the difference between a scanner and an autonomous pentester.
- 2026-04-25
Scope is a runtime concern, not a checkbox
How egress allowlists, policy_check, and append-only audit logs combine into a defense-in-depth model.
- 2026-04-12
Orchestrator/worker agent patterns
Why long-lived Opus + short-lived Haiku beats every-shot-the-same in our benchmarks.