2026-07-23 · Company
Why we started Faultline
A short note on the problems we want to help European teams fix first.
Notes
Technical write-ups. No product pitch, just the work.
2026-07-23 · Company
A short note on the problems we want to help European teams fix first.
2026-07-18 · AI red teaming
Yellow teams build the harnesses that make AI red teaming actually work, instead of just generating noise. What that means for SaaS teams evaluating AI security testing and build-versus-buy decisions.
2026-07-14 · AI red teaming
Orphaned AI agents keep production access after their creators leave, and traditional audits miss them. How SaaS teams inventory agents, scope permissions, and test for prompt injection before attackers do.
2026-07-09 · Compliance
A buyer-led framing of market expectations, not a standard-by-standard law lesson.
2026-07-07 · Application security
CVE-2026-8451 was exploited within 24 hours of WatchTowr Labs publishing a PoC. Why the patch-deploy gap makes reactive security fail for authentication infrastructure, and what proactive testing finds first.
2026-07-04 · SaaS security
Apple just proved the AI exploit patching cycle is real. Why annual pentests are compliance theater, and what testing cadence actually keeps up with AI-accelerated attackers.
2026-06-25 · Application security
OWASP, abuse cases, and how to pair automated signals with a focused manual review.
2026-06-11 · SaaS security
What to prioritise in the 12-24 month window: identity, data, and vendor risk without boiling the ocean.
2026-06-03 · Pricing
From pricing signals to what actually moves the number for B2B SaaS.
2026-05-27 · AI red teaming
Most SaaS companies fund AI agent identity security from the wrong budget. Here is what it actually costs and how to plan for it.
2026-05-22 · AI red teaming
What the Claw Chain vulnerabilities in OpenClaw reveal about AI agent attack surfaces, and what SaaS teams should be testing before they ship.
2026-05-14 · Pentest process
Deliverables, common coverage, and the difference between tiers in plain language.
2026-04-30 · Pentest process
Scoping, calendar time, and what the typical windows look like for SaaS teams.
2026-04-29 · Compliance
What auditors expect, when a pentest is in scope, and what you can de-risk without a full test.
2026-04-28 · Application security
CVE-2025-29927 is patched. Three specific Next.js auth patterns it exposed are not. How to audit your own app for each one.