Bring Product Security into focus.
I work with software companies on the security questions that sit between leadership, product, and engineering. Together, we establish what the product needs to protect and turn that into a coherent direction for architecture, delivery, customer conversations, and future decisions.
Recent writing
Notes from the work
01
Proxmox Community Scripts are a bad idea
I've been running Proxmox for quite some time now to host my business-critical infrastructure. This includes services like Nextcloud, Vaultwarden and Authentik, most of which...
2026-09-22
02
AI doesn't eliminate the cost of owning software
I'm deep into reading papers about AI, mostly with regard to secure code generation and trust in AI models. Compared with the enormous amount of dfiscussion around AI...
2026-09-02
03
AI still doesn't consider security proactively
AI has improved substantially over the last few years, and AI coding agents are now widely used. They play a significant role in all of my recent projects, from the Weekplanner...
2026-09-01
04
Your legacy API isn't the problem. Your documentation is.
For many mid-sized companies, an API exists somewhere in the system. It might have started years ago as an internal tool. Maybe it was built quickly to satisfy a one-off partner integration. Over time, it stayed in place, but the company changed. Teams grew. Partnerships became more valuable. And suddenly, the API became a commercial asset.
2025-07-30
A few words from others
“Søren quickly grasped the technical and business context of our project and added value from day one. His strong engineering background and structured thinking made collaboration seamless.”
“Søren provided clear, strategic guidance and valuable resources, making complex challenges easier to navigate. His mentoring and communication skills are a real asset for anyone seeking advisory support.”
About
I’ve spent more than a decade building software and looking closely at how it fails.
That has included multi-tenant platforms used by millions of people, identity systems, application and API security, and the less glamorous work of turning an old pentest finding into something an engineering team can actually fix and verify.
I now work independently with European software companies. I also build RecoveryCodes, which keeps me on the vendor side of the table, where security claims eventually have to meet a real product and a real customer.