Security, Auth, and Compliance
Auth, compliance, OWASP, and the security work that enterprise buyers will ask about on day one.
46 posts · page 2 of 2
- Security, Auth, and Compliance
Data Residency for International SaaS: A Real Plan
Data residency is one of those compliance requirements that turns into engineering reality the moment an enterprise customer asks. Plan for it before. The retrofit is much harder than the original design.
12 min read
- Security, Auth, and Compliance
Customer Managed Encryption Keys: Enterprise Engineering
Customer managed encryption keys are the enterprise feature most SaaS teams build last and discover they needed sooner. Here is the architecture, the cost, and the trade offs.
13 min read
- Security, Auth, and Compliance
CSRF, XSS, SSRF: A Modern Web Security Primer
Three of the most common web vulnerabilities in 2026 are still CSRF, XSS, and SSRF. The frameworks help with some. The team has to handle the rest. Here is the modern read on each.
12 min read
- Security, Auth, and Compliance
Cookie Compliance Without Killing Conversion
The standard cookie banner is a conversion killer. Compliant alternatives exist. The teams that take this seriously preserve compliance and conversion. The teams that do not lose either or both.
11 min read
- Security, Auth, and Compliance
Building a Security Program From Zero: A Twelve Month Plan
A real security program is twelve months of compounding decisions. The shortcut is missing the work, not skipping it. Here is the month by month plan I have used with clients to get from zero to a defensible posture.
13 min read
- Security, Auth, and Compliance
Backup and Restore Drills: A Compliance Asset Most Teams Skip
A backup is only as good as the last successful restore drill. Most teams have backups. Few teams run drills. The drill is what turns the backup from a checkbox into a real control.
12 min read
- Security, Auth, and Compliance
Authorization Patterns: RBAC, ABAC, ReBAC Explained
RBAC is the default. ABAC is what you reach for when the rules get conditional. ReBAC is what you actually want for B2B SaaS with hierarchical resources. Here is when each one earns its keep.
12 min read
- Security, Auth, and Compliance
Audit Trails for Sensitive Actions: The Pattern That Earns Trust
An audit trail on sensitive actions is the single feature most likely to swing an enterprise security review. Most teams underbuild it. Here is the pattern that earns trust, the cost, and the trade offs.
12 min read
- Security, Auth, and Compliance
Audit Logs That Pass Real Audits
Most teams build audit logs for SOC 2 and stop there. The ones that pass real audits, year after year, treat the audit log as a product. Here is how I build them.
13 min read
- Security, Auth, and Compliance
API Key Rotation Without Customer Outages
Rotating API keys without breaking integrations is a discipline more than a technology. The pattern that works for me on client projects is overlap, notice, deprecation, and observability.
10 min read
- Security, Auth, and Compliance
API Authentication in 2026: API Keys, JWTs, OAuth, mTLS
Four authentication schemes, four very different threat models. The right choice depends on who you trust, how you rotate, and how much pain you can absorb. Here is the call I make per project.
12 min read
- Security, Auth, and Compliance
The Data Processing Agreement: A Founder's Practical Read
What a DPA actually requires, why enterprise buyers demand it before signing, and how to get one done without a full legal team.
12 min read
- Security, Auth, and Compliance
The Post Mortem Culture That Improves Security
A post mortem is only useful if the team reads the findings and changes something. Most teams file the document and repeat the incident. Here is the pattern that actually moves the security needle.
12 min read
- Security, Auth, and Compliance
The Customer Security Questionnaire: A Strategic Asset
Why the security questionnaire is not a compliance checkbox but a sales asset, and how to build answers that close enterprise deals faster.
12 min read
- Security, Auth, and Compliance
Vendor Security Assessments: How to Pass Them Quickly
Most vendor security assessments ask the same questions in slightly different forms. A startup that prepares once can answer the next dozen in a day each. The slow path is treating each one as a surprise.
11 min read
- Security, Auth, and Compliance
The Privacy Policy That a Lawyer Actually Approved
Most startup privacy policies are either copied from a competitor or generated by a free tool and never reviewed by counsel. Both approaches create real liability. Here is what it actually takes to have a policy that holds up.
11 min read
- Security, Auth, and Compliance
The Threat Model: How to Build One in Two Hours
A threat model does not have to be a hundred-page document. A useful one fits on a whiteboard, takes two hours to build, and changes how the team makes security decisions for months. Here is the format I use.
13 min read
- Security, Auth, and Compliance
The Permission System That Scales With Your B2B Customers
Most B2B permission systems break when the second enterprise customer asks for a different role model. Building it right from the start means picking the right abstraction, not the fastest one.
12 min read
- Security, Auth, and Compliance
The Bug Bounty Decision: When You Are Ready, When You Are Not
How to decide if your SaaS is ready for a bug bounty program, what readiness actually looks like, and what happens when you launch one too early.
12 min read
- Security, Auth, and Compliance
Vulnerability Disclosure Programs: Why Even Small Teams Need One
A vulnerability disclosure program is a public commitment to listen when someone finds a security issue in your product. It costs nothing and prevents the worst version of every incident. Most teams skip it because they have not thought about what they will do when a researcher emails them.
11 min read
- Security, Auth, and Compliance
The Single Tenant Argument: When Enterprise Customers Demand It
Enterprise customers who demand single tenant deployments are not being irrational. They are making a calculation about data isolation and audit scope. Here is how to evaluate the request and when to say yes.
11 min read
- Security, Auth, and Compliance
The Security Gap: How One Missing SOC 2 Control Kills Your Enterprise Deal
Enterprise buyers do not walk away from deals because your security is bad. They walk away because one specific gap appears in the security questionnaire and nobody can answer it. Here is how to find that gap before they do.
12 min read