Blog
Engineering, security leadership, responsible AI, and open source.
Product security has to work with the product
Security has to be engineered as part of the system, not bolted on as a checklist — with functional proof, resource-impact proof, and deployment evidence as the definition of done.
From CVE scanning to actual vulnerability management
CVE scanning gives visibility into an embedded image. It doesn't tell you what to do about it — that takes product context, evidence-based triage, and proof that a fix actually reached the device.