Back to site
Blog
RSSSecurity notes & build logs
Things I learn while hardening systems, hunting vulnerabilities and shipping software — written up so they're useful beyond my own notes.
14 Sept 20261 min read
RBAC is harder than it looks
Role-based access control sounds simple until you have multi-tenant data, sensitive documents, and five modules that all have to agree.
AppSecRBACMulti-tenant
Read post14 Sept 20261 min read
Detecting scam SMS with a fine-tuned Polish transformer
Why a generic model was not enough for Polish-language fraud, and how the alert flow protects the people most often targeted.
Machine LearningNLPFraud
Read post