Field notes from the work itself.
Short write-ups pulled from engagements once they're fully closed out and anonymized. No client names, no identifying details — just the pattern, so other teams can check themselves against it.
Session tokens surviving password resets
A recurring pattern across three unrelated audits this quarter: password reset flows that invalidate the password but leave every existing session token active. An attacker who already has a token keeps access indefinitely.
Third-party SDKs quietly widening data collection
Analytics and crash-reporting SDKs updating their own collection scope in minor version bumps, without changing your app's privacy posture on paper. Pin versions, diff manifests.
All field notes.
Full technical write-ups, reproduction steps and affected version ranges are shared directly with impacted parties and under NDA on request. Public notes here are intentionally stripped of anything actionable.
Request a report →