Posts about #security

16 posts

3 min read

We Teardown AI-Generated Web Apps: The 3 AI-Specific Security Mistakes

An empirical teardown of AI-generated web apps. We looked for the failures that only happen when code is vibed — Supabase RLS gaps, AI API keys shipped to the browser, and login forms generated with insecure defaults. Here's what we found and how to fix each one.

#security#ai-code#vibe-coding#supabase#api-keys#teardown
5 min read

How Vergate's GitHub integration works — and why it's privacy-respecting by design

A technical deep-dive into Vergate's GitHub App: the webhook architecture, JWT-signed installation tokens, Check Run feedback in your PRs, and exactly what we do — and don't — read from your repositories.

#github#github-app#code-scanning#ci-cd#webhooks#security
5 min read

Security Headers Explained: The Complete 2026 Guide

Every HTTP security header decoded — what it does, what to set, common mistakes, and how to audit your site in seconds. Covers CSP, HSTS, X-Frame-Options, and more.

#security#security-headers#csp#hsts#web-security
5 min read

How to Audit a Next.js App for Security Misconfigurations and Header Leaks

Default Next.js production setups leak server runtime info, misconfigure CORS, and expose internal routes. Here's the audit — inspect headers, find env leaks, verify CORS — with code fixes for next.config.js.

#nextjs#security#headers#cors#audit#vercel
4 min read

Lightweight Web Auditing vs. OWASP ZAP: Choosing the Right Security Workflow

OWASP ZAP is powerful but heavy — complex setup, minutes per scan, massive false positives. Here's when to use ZAP, when to use lightweight scanners, and how to build a layered security workflow.

#security#owasp-zap#scanner#ci-cd#devops
7 min read

How to Pass a Security Audit: The Practical Playbook

Everything you need to pass a website security audit — from vulnerability scanning to compliance checklists, penetration testing prep, and remediation strategies that actually work.

#security#compliance#penetration-testing#vulnerability-scanning#web-security
4 min read

FastAPI Production Checklist: CORS, Rate Limiting, and Diagnostic Monitoring

FastAPI is fast to build with, but production-ready middleware is often left as an afterthought. Here's the checklist for CORS, exception leakage, async pitfalls, and structured logging.

#fastapi#python#security#cors#monitoring#production
5 min read

We Audited 50 Popular Web Applications: The Top 4 Security Mistakes We Found

An empirical teardown of 50 real websites. 68% lacked proper CSP or HSTS, 30% leaked stack traces on malformed input, 25% had public staging endpoints, and 17% had broken TLS chains. Here's what we found and how to fix it.

#security#audit#web-applications#headers#tls#findings
3 min read

How we handle vulnerability reports (and what we'd do with yours)

We're a security company, so people poke at our product. Here's our published policy: what we promise reporters, what's in scope, how fast we respond, and the safe-harbor commitment that makes it safe to tell us we're wrong.

#disclosure#security#responsible-disclosure#policy
3 min read

We want you to leave us (until you shouldn't)

The un-marketing post: exactly when you should NOT use Vergate — one-off audits, penetration tests, keyword research, simple static sites. Because a customer who stays because we tricked them is a customer who leaves angry.

#honesty#positioning#comparison#security
4 min read

We scanned our own site and found real problems. Here's everything.

Dogfooding isn't a marketing stunt — it's embarrassing. Our own scanner found 8 real issues on vergate.dev (including zero security headers), we fixed them, and we learned something about our own hosting provider along the way.

#dogfooding#security#security-headers#transparency
3 min read

The 5-minute pre-deploy security checklist (for anyone shipping fast)

You're about to push to production. You have five minutes. Here's the exact checklist — free scan, headers, exposed files, secrets, deps, redirects, cookies — that catches the majority of real-world breaks before your users do.

#security#checklist#devops#ci
3 min read

Audit us: our engine is open, our reports are signed, and we'll show you the receipts

Every security claim on the internet is a trust claim. Here's how Vergate makes trust verifiable instead of vibes: an open engine, evidence on every finding, tamper-evident signed reports, and the time our own scanner caught our own mistakes.

#transparency#trust#security#open-source
3 min read

Know Your Stack: Technology Profiling Is a Security Practice

You can't secure what you don't know is running. Technology profiling turns your stack into an asset — for CVEs, compliance, and cleanup.

#profiling#supply-chain#security
3 min read

The Security Headers Every AI-Built Site Needs

Missing security headers are an instant fail on any scan. Here's the exact header set for AI-built sites, what each one does, and how to set them.

#security#headers#vibe-coding
4 min read

Vibe Coding Security: What Every AI-First Dev Should Know

AI writes code fast — and fast is exactly when security gaps slip in. Here's how to ship AI-generated code without shipping vulnerabilities.

#security#vibe-coding#ai