Søren Johanson
Product Security Assessment Articles Discuss an assessment

Notes about Security

A collection of articles about product security, software engineering, and building reliable products.

Latest Proxmox Community Scripts are a bad idea

I've been running Proxmox for quite some time now to host my business-critical infrastructure. This includes services like Nextcloud, Vaultwarden and Authentik, most of which...

2026-09-22

Read more

AI doesn't eliminate the cost of owning software

I'm deep into reading papers about AI, mostly with regard to secure code generation and trust in AI models. Compared with the enormous amount of dfiscussion around AI...

2026-09-02

AI still doesn't consider security proactively

AI has improved substantially over the last few years, and AI coding agents are now widely used. They play a significant role in all of my recent projects, from the Weekplanner...

2026-09-01

Your legacy API isn't the problem. Your documentation is.

For many mid-sized companies, an API exists somewhere in the system. It might have started years ago as an internal tool. Maybe it was built quickly to satisfy a one-off partner...

2025-07-30

API security consultant accidentally exposes own credentials: a post-mortem

Yesterday, I got an automated email from Brevo telling me that someone's trying to access the Brevo API using my API key.

2025-07-09

Page 1 of 7 Next →
Søren Johanson

Product Security Engineering for European B2B software vendors moving upmarket.

Product Security

  • Product Security
  • Product Security Assessment
  • Articles

Resources

  • Product Security vs Application Security
  • What is Product Security Engineering?
  • Security Remediation and Vulnerability Retesting
  • Continuous Product Security Assurance
  • Product Security for B2B SaaS

© Søren Johanson 2026. All rights reserved.

Terms Privacy policy Legal notice