Blog

Long-form on security, cryptography, and trust.

We write when we have something specific to say — about a threat model, a design decision, or a reason the industry default is worse than it looks. Each piece is deliberately long enough to actually make its argument.

Security

Your secrets deserve to be invisible

Why a vault should be invisible, not just encrypted — LastPass, local-first architecture, steganography, and honest limits.

More posts are in progress. The next few are on device-bound vaults, the limits of cloud-zero-knowledge, and our security review process.