Representative Foreword

After the Code, the Structure Remains

The representative foreword of this blog: security now fails less at finding issues than at absorbing, sustaining, and acting on what has already been found.

This essay frames the entire site first. The posts on technical analysis, method, and governance all start from this same problem statement.

After the Code, the Structure Remains

Detection, Method, Governance

🔥 A Mind That Dissects Systems

🔥 Trust and Culture Beyond Technology

🔥 Code That Fixes, Not Just Runs

AI trust boundaries around a package and container registry proxy

AI Package and Container Registry Boundaries: Egress Control Architecture for AI Runtimes

Package and container registry proxies are active trust boundaries for AI runtimes. This report turns incident evidence, public SSRF history, and runtime observations into an artifact egress control architecture.

July 27, 2026 · 16 min · 3246 words

The Limitations of 'Secure' SSRF Patches: Advanced Bypasses and Defense-in-Depth

A deep dive into why common SSRF defense code is often incomplete, real-world bypasses, and practical, layered mitigation strategies for developers and security engineers.

June 25, 2025 · 21 min · 4291 words