Insights on data security

No fluff. Technical depth, compliance context and real-world scenarios.

The DSAR That Takes Fifteen Minutes

Why a single subject access request can consume a week of engineering time — and what changes structurally when personal data stops being scattered.

2026-08-30

Encryption at Rest Is Not Protection

"The database is encrypted" answers a question almost nobody is asking. What encryption at rest actually defends against — and the four ways data leaks around it.

2026-08-16

The Accidental PII Vault

Nobody decides to build a PII vault. Every company running for a few years has one anyway — scattered across services, maintained by payroll, invisible on the roadmap.

2026-08-02

GDPR Article 17 — The Right to Erasure Is Not a Delete Button

Most companies think a delete button satisfies GDPR Art.17. It doesn't. Here's what compliant erasure actually requires technically — WAL, replicas, backups, and all.

2026-07-22

The Delete Button That Doesn't Delete Anything

Your admin panel has a delete button. Your privacy policy references it. When a user invokes GDPR Article 17 — it doesn't do what you think it does.

2026-04-06

Your Cloud Provider Can Read Your Data. You Agreed to It.

There is a clause in your cloud provider agreement. You clicked Accept. Here is what it actually says.

2026-03-26

The Monday Morning That Changes Everything

Your security admin left on Friday. A major client calls Monday morning about a potential breach. You have no answers. What's your plan for that Monday morning?

2026-03-13