No thought-leadership, no news. Just the architecture, the threat models and the decisions behind SafeHanded, in enough detail to argue with.
Four pieces, each drawn straight from the work in the product. We'd rather publish these four honestly than backdate a year of posts we never wrote.
The I-1 invariant and the automated test that walks every response and fails the build if an envelope field, link token or recovery code ever leaks. Marketing writes a claim; a test enforces it.
Read →A walkthrough of the standalone, dependency-free verifier and the per-credential chain-of-custody certificate, and how you'd prove to an auditor that a chain wasn't tampered with, on your own machine.
Read →Treating the ticket lifecycle as a security control, not a convenience. How the record is created from a ticket, noted back at each step, and purged when the ticket closes, across every PSA adapter.
Read →These essays publish as the site goes live. Want the security detail now? It's already on the security page →
Read the full security model, or start on the free plan and put a credential through it end to end.