Blog
Notes on finding real bugs
How we think about application security, agentic code review, and why most of the work is in throwing findings away.
Latest 3 min read
What a scan actually costs, and how to control it
Scan depth, reasoning level, flow budgets and per-stage model selection are the four knobs that decide what a Parlix run costs. Here's how to set them.
guide operations
Read the post
3 min read
Verifying a vulnerability before reporting it
A candidate finding and a vulnerability are different objects. Here's the verification stage that separates them, and why it deletes more than it keeps.
engineering verification
3 min read
Why most security scanners get ignored
Every team has a scanner. Almost no team reads its output. The problem isn't discipline — it's that precision below a certain threshold makes a tool worse than useless.
appsec tooling