Our Blog

Notes from the work

What we have learned building and rescuing products for SaaS companies and startups — architecture, AI, security, delivery. No listicles, no reheated press releases.

Showing articles tagged “security”. Clear filter

Ruby & Rails

Rails 8.2: CSRF Without Tokens

Sec-Fetch-Site replaces the authenticity token, Rails.app.revision arrives for monitoring, and Argon2 lands in has_secure_password. What actually changes in your application.

Read
E-Commerce

The Usefulness of a Payment System

Taking money is easy. Taking money reliably, refunding it, reconciling it and staying out of PCI scope is the part that takes a quarter. What a payment system really has to do.

Read
Security

Web Security: The Defences That Earn Their Keep

Most breaches are not clever. They are a missing check on a route nobody remembered. A practical tour of the OWASP risks that actually reach production, and the layered defences that stop them.

Read