security advisory · ai era

Building security into software — before and after the AI wrote it.

Independent security advisory for teams shipping fast with AI. Thirty years from chip-level cryptography to enterprise AppSec — now focused on doing AI-assisted development without the slop.

scroll
what i do 01 / services

Secure AI-assisted development

Adopt Copilot, Cursor and the rest without shipping AI slop. Guardrails, review workflows, and remediation for AI-generated code.

AppSec & DevSecOps programmes

Build or scale security into your SDLC — the playbook that ran across 5,000+ apps at Deutsche Bank, sized to your org.

API & product security

Architecture reviews, threat modelling, and hands-on API security from the author of Defending APIs.

track record 02 / experience

Three decades, end to end — from hardware security modules to one of the largest enterprise AppSec programmes on record.

Deutsche BankVolkswagenLG ElectronicsVeracode42CrunchRandstadnCipher / ThalesSidekick SecurityDeutsche BankVolkswagenLG ElectronicsVeracode42CrunchRandstadnCipher / ThalesSidekick Security

Author of Defending APIs (Packt, 2024) · former Chief Technology Evangelist, 42Crunch · ISC2 CSSLP

what i'm researching 03 / research

Secure AI software development

The glass-half-full case for AI-assisted development — honest about the risk, optimistic about the craft. Patterns, guardrails, and how to clean up after the model.

Deep dives are moving to Defending Dev — coming soon
contact

Let's talk.

I take on a small number of advisory engagements — retainer, project, or a few days here and there as a trusted pair of hands.

Get in touch