Notes about Security
A collection of articles about product security, software engineering, and building reliable products.
Managing API secrets: Beyond environment variables
Most security breaches don't start with sophisticated hackers - they begin with digital keys to your business systems left lying around in the wrong places, like passwords...
2025-06-25
How to tackle OWASP API security risks with minimal resources
How do you tackle all OWASP API security risks when your engineering team is already stretched thin?
2025-06-18
API rate limiting: The security feature that actually improves UX
The security features your customers actually appreciate are the ones they never notice - until they protect them from themselves.
2025-06-11
Zero-day resilience: API design patterns that survive unknown threats
The most dangerous API vulnerabilities aren't the ones we know about - they're the ones still waiting to be discovered.
2025-06-04
Securing GraphQL APIs: Avoiding the pitfalls startups miss
GraphQL adoption has grown massively among startups in the last few years, yet most API security guidance remains firmly REST-centric. This creates a dangerous blind spot as...
2025-05-28