Field notes
Writing from the review desk
Practical notes for engineering leads commissioning cybersecurity code audits.
Why we read authentication before features
Feature modules get the spotlight, but session and identity code still decides who can reach them. Here is how our audits sequence that work.
Lockfiles tell more honest stories than READMEs
Manifest files describe intent. Lockfiles describe what actually shipped. Auditors lean on the latter when ranking supply-chain risk.
Staging evidence beats screenshots in findings
Developers fix what they can reproduce. Our reports favour steps that run in staging over dramatic screenshots alone.
Scope documents that survive handoffs
Audits stall when repositories multiply mid-engagement. A crisp scope document keeps both sides honest.