Product Security in the Real World
The gap between "we have a threat model" and "we're actually secure" is where most of this blog lives.
September 9, 2026
Cloudflare Just Validated What We've Been Building for Medical Devices
Cloudflare's new vulnerability discovery and remediation service highlights the same truth we have been building around: product context changes risk. In medical devices, context-aware triage is the difference between a real risk and a scanner-driven panic.
Read post →September 1, 2026
Your Engineers Won't Stop Using Excel. That's Fine.
Engineers keep going back to Excel. That's not the real problem. Here's what actually breaks when your security data lives in disconnected spreadsheets — and what it means for FDA submissions.
Read post →August 18, 2026
CVSS Scores Are Lying to You
CVSS scores describe how bad a vulnerability could be in theory. They say nothing about your product. Here's why context is everything in vulnerability triage.
Read post →August 5, 2026
We Built an API Into Our Security Platform. Then We Connected Claude Code.
PSH started as a web app. Then we built a full REST API — and connected Claude Code to it. Here's what changed about how we work.
Read post →August 4, 2026
The FDA Wants Traceability, Not Documents
The FDA doesn't want PDFs. They want connected evidence. Here's why traceability is infrastructure, not paperwork — and what it looks like when it actually works.
Read post →