Posts about #security
16 posts
We Teardown AI-Generated Web Apps: The 3 AI-Specific Security Mistakes
An empirical teardown of AI-generated web apps. We looked for the failures that only happen when code is vibed — Supabase RLS gaps, AI API keys shipped to the browser, and login forms generated with insecure defaults. Here's what we found and how to fix each one.
How Vergate's GitHub integration works — and why it's privacy-respecting by design
A technical deep-dive into Vergate's GitHub App: the webhook architecture, JWT-signed installation tokens, Check Run feedback in your PRs, and exactly what we do — and don't — read from your repositories.
Security Headers Explained: The Complete 2026 Guide
Every HTTP security header decoded — what it does, what to set, common mistakes, and how to audit your site in seconds. Covers CSP, HSTS, X-Frame-Options, and more.
How to Audit a Next.js App for Security Misconfigurations and Header Leaks
Default Next.js production setups leak server runtime info, misconfigure CORS, and expose internal routes. Here's the audit — inspect headers, find env leaks, verify CORS — with code fixes for next.config.js.
Lightweight Web Auditing vs. OWASP ZAP: Choosing the Right Security Workflow
OWASP ZAP is powerful but heavy — complex setup, minutes per scan, massive false positives. Here's when to use ZAP, when to use lightweight scanners, and how to build a layered security workflow.
How to Pass a Security Audit: The Practical Playbook
Everything you need to pass a website security audit — from vulnerability scanning to compliance checklists, penetration testing prep, and remediation strategies that actually work.
FastAPI Production Checklist: CORS, Rate Limiting, and Diagnostic Monitoring
FastAPI is fast to build with, but production-ready middleware is often left as an afterthought. Here's the checklist for CORS, exception leakage, async pitfalls, and structured logging.
We Audited 50 Popular Web Applications: The Top 4 Security Mistakes We Found
An empirical teardown of 50 real websites. 68% lacked proper CSP or HSTS, 30% leaked stack traces on malformed input, 25% had public staging endpoints, and 17% had broken TLS chains. Here's what we found and how to fix it.
How we handle vulnerability reports (and what we'd do with yours)
We're a security company, so people poke at our product. Here's our published policy: what we promise reporters, what's in scope, how fast we respond, and the safe-harbor commitment that makes it safe to tell us we're wrong.
We want you to leave us (until you shouldn't)
The un-marketing post: exactly when you should NOT use Vergate — one-off audits, penetration tests, keyword research, simple static sites. Because a customer who stays because we tricked them is a customer who leaves angry.
We scanned our own site and found real problems. Here's everything.
Dogfooding isn't a marketing stunt — it's embarrassing. Our own scanner found 8 real issues on vergate.dev (including zero security headers), we fixed them, and we learned something about our own hosting provider along the way.
The 5-minute pre-deploy security checklist (for anyone shipping fast)
You're about to push to production. You have five minutes. Here's the exact checklist — free scan, headers, exposed files, secrets, deps, redirects, cookies — that catches the majority of real-world breaks before your users do.
Audit us: our engine is open, our reports are signed, and we'll show you the receipts
Every security claim on the internet is a trust claim. Here's how Vergate makes trust verifiable instead of vibes: an open engine, evidence on every finding, tamper-evident signed reports, and the time our own scanner caught our own mistakes.
Know Your Stack: Technology Profiling Is a Security Practice
You can't secure what you don't know is running. Technology profiling turns your stack into an asset — for CVEs, compliance, and cleanup.
The Security Headers Every AI-Built Site Needs
Missing security headers are an instant fail on any scan. Here's the exact header set for AI-built sites, what each one does, and how to set them.
Vibe Coding Security: What Every AI-First Dev Should Know
AI writes code fast — and fast is exactly when security gaps slip in. Here's how to ship AI-generated code without shipping vulnerabilities.