// WE PUBLISH WHAT WE LEARN
Research & Analysis
Original computation on public data. Experiments with reproducible setups. Novel findings when we earn them. Every piece is labeled for exactly what it is.
Analysis
7
MIN READ
Why AI-Built Apps Need a Different Pentest
AI writes code faster than anyone secures it, and the failure modes are new. Prompt injection, over-permissioned agents, secrets in generated code, and attacks on the AI assistant itself sit outside a standard pentest. Here is what testing an AI-built app should actually cover.
READ THE FULL PIECE ->
Analysis
6
MIN READ
Does SOC 2, ISO 27001, or PCI DSS Require a Penetration Test?
PCI DSS explicitly requires penetration testing; SOC 2, ISO 27001, and HIPAA do not name it but expect it in practice. A framework-by-framework answer on where a pentest is mandatory versus strongly expected.
READ THE FULL PIECE ->
Analysis
6
MIN READ
Does AI Actually Make SOC 2 Faster? We Fact-Checked the Compliance Vendors
Every compliance automation vendor claims AI makes SOC 2 dramatically faster - "50% less work", "80-90% faster evidence collection", "weeks instead of months". We compiled the quantified claims from the top-ranking pages and checked which ones disclose any methodology. Most don't. Here is what is actually substantiated, and the one thing about SOC 2 timelines that no AI can compress.
READ THE FULL PIECE ->
Analysis
8
MIN READ
Securing AI-Generated Code: What 23 Studies and 48,185 CVEs Actually Show
We reviewed 23 studies and industry datasets on AI-generated code security. Roughly one in three AI-generated code samples contains a vulnerability - a rate that has not improved across model generations - while CVE publications grew 139% in the four years AI went from writing none of our code to roughly a third of it. Here is what the evidence says actually works.
READ THE FULL PIECE ->
Analysis
6
MIN READ
Annual Pentests Would Have Missed 67% of 2025's Actively Exploited Vulnerabilities
We computed the disclosure-to-exploitation window for all 245 vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog in 2025. The median window is 26 days. Under an annual pentest schedule, an expected 67.5% would never be tested before exploitation - and quarterly testing still misses 54%.
READ THE FULL PIECE ->