Guides
Reference pages we keep correct, rather than dated commentary. Each one answers a question directly, names the standards behind it, and says where the answer stops.
How to check an AI-built app before you launch
The order to check an AI-built application in before real users arrive, what each check can establish on your own, and the point where checking it yourself stops being enough.
AI-generated code vulnerabilities: what actually goes wrong
The vulnerability classes that turn up most often in AI-generated code, what each one looks like in practice, how it is found, and which of them a scanner can settle on its own.
How to evaluate a vendor's technical claims without being technical
A practical method for non-technical executives assessing what a software vendor says about its security and reliability, the questions that separate evidence from assertion, and where training actually exists.
A security review prompt for vibe-coded apps, and what it cannot tell you
A prompt you can paste into your AI coding tool to review a vibe-coded app for the failures that matter, plus an honest account of the four things no prompt can establish.
The startup technical audit: what it covers and when you need one
What a startup technical audit actually examines, what it costs at seed and Series A, when it is worth doing, and how to prepare so the findings are useful rather than embarrassing.
The technical due diligence questions investors actually ask
What technical due diligence covers at seed and Series A, the questions that come up in almost every process, what a good answer looks like, and how to prepare before the process starts.
Is my Lovable app secure enough to launch?
A practical pre-launch security check for apps built with Lovable, covering the four failure modes that account for most real incidents, how to test each one yourself, and what to do about them.