Notes from
the architecture.
Working notes on secure system design, threat modeling, delivery hardening, and the security of AI platforms.
What TLS actually protects, and what it doesn't
The padlock means less than people assume. What TLS guarantees, what it never covered, and the misconfigurations that quietly remove those guarantees.
SSO, OAuth, and JWT: what each one actually does
These three get used interchangeably and they are not the same thing. What each layer is responsible for, and the mistakes that follow from confusing them.
How to run a threat model people actually use
Threat modeling fails when it produces a document instead of decisions. A practical walkthrough of scope, trust boundaries, STRIDE, and useful output.