Skip to content
Top Notchh.
Journal · 30 notes · Company memory

Filed under verglos.

Every note is attached to a product, a scan, or a real operational pattern we watched play out in the field. We publish when we have something specific to say — never on a content calendar.

Filtered notes

Layered authorship traces converging on one neutral security finding.

Verglos · Architecture

AI-authorship provenance, explained

Why probable AI authorship can be useful review context without becoming a vulnerability label, blame mechanism, or substitute for code evidence.

Aug 20, 2026 · 1 min readRead
A sealed local workstation testing one evidence path inside a constrained chamber.

Verglos · Design note

The local sandbox verification concept behind Verglos

A design note for bounded local finding verification, including what exists in Verglos alpha and what still has to be built safely for review.

Aug 20, 2026 · 3 min readRead
A compact evidence package receiving an integrity seal before a client handoff.

Verglos · Product proposal

Signed evidence artifacts are the proposed Studio wedge

A product-design note on portable, signed security summaries, with Verglos' unshipped status and trust requirements stated directly for agencies.

Aug 20, 2026 · 2 min readRead
Invented package labels approaching a guarded software registry checkpoint.

Verglos · research note

Slopsquatting in 2026: the numbers that matter

What the primary package-hallucination study measured, what it did not measure, and how JavaScript developers can reduce installation risk before install.

Aug 20, 2026 · 2 min readRead
A working scanner instrument beside two clearly unfinished evidence modules.

Verglos · Release note

Verglos 2.0 alpha: scanner today, evidence direction next

The honest boundary of Verglos 2.0.0-alpha.1: a functional local scanner, command shells for hunt and attest, and a roadmap that is not yet product truth.

Aug 20, 2026 · 1 min readRead
Four product-model columns with only the local scanner marked as currently available.

Verglos · Product proposal

The proposed Verglos Free, Pro, Studio, and Enterprise model

A transparent Verglos product-model draft that separates the local alpha from unbuilt paid tiers and avoids invented prices or entitlements.

Aug 20, 2026 · 1 min readRead
A local scanner and a connected security platform balancing privacy against organization-wide context.

Verglos · Comparison

Verglos vs cloud SAST: the trust-model tradeoff

A comparison of Verglos local scanning and hosted application-security platforms based on workflow, context, governance, and evidence needs.

Aug 20, 2026 · 2 min readRead
A local scanner inside four clear boundaries marking excluded product directions.

Verglos · Product principle

What Verglos 2.0 alpha refuses

Four product boundaries for Verglos: no autonomous attacks, no cloud requirement for scanning, no compliance theater, and no roadmap passed off as shipping.

Aug 20, 2026 · 1 min readRead
An external offensive-testing route and a local code-review route diverging from a shared security question.

Verglos · Positioning

Why Verglos refuses the XBOW lane

XBOW and Verglos address different security jobs: authorized autonomous offensive testing versus a narrow local scanning and evidence direction.

Aug 20, 2026 · 1 min readRead
One local scanner feeding separate terminal, review, and continuous-integration checkpoints.

Verglos · field guide

Verglos on the CLI, with coding agents, and in CI

The supported Verglos local scan path and conservative ways to place it around agent and CI workflows without inventing integrations or claims.

Aug 19, 2026 · 1 min readRead
A local evidence instrument stopping at a firm boundary before an external attack surface.

Verglos · Product principle

Why Verglos will not ship an attacking agent

The authorization, reproducibility, and trust reasons Verglos separates local evidence work from autonomous offensive testing in the current alpha.

Aug 19, 2026 · 1 min readRead
Eight distinct breaks in a miniature application-security system.

Verglos · Research

Eight patterns AI-assisted code keeps producing

Eight reviewable vulnerability shapes that recur in fast-built JavaScript and TypeScript, plus the control that should catch each one in review.

Jul 30, 2026 · 9 min readRead
Repository blocks passing through a scanner into grouped evidence trays.

Verglos · Research

What our 300-repository TS/JS scan did and did not show

A corrected account of the Verglos scan campaign, its published artifacts, its 57.7% high-or-critical result, and the limits on interpreting scanner output.

Jul 30, 2026 · 13 min readRead
Several specialized security instruments surrounding a small local scanner without a winner's podium.

Verglos · Comparison

Verglos alongside Snyk, GitHub, Semgrep, Socket, and Gitleaks

A capability-bound comparison showing where a narrow local alpha scanner may complement established code, dependency, and secret-security tools.

Jul 25, 2026 · 9 min readRead
Layered security records connecting source review, findings, decisions, and a handoff artifact.

Verglos · thesis

The security evidence layer for AI-built software

Why AI-assisted software needs reviewable security records, and which parts of Verglos' evidence model exist for builders and teams in alpha today.

Jul 24, 2026 · 2 min readRead
Redacted evidence moving through a private disclosure and key-rotation chain.

Verglos · Field note

Responsible disclosure when a scan finds a live credential

A conservative workflow for containment, private outreach, rotation, patch verification, and delayed publication after a scanner finds a possible live secret.

Jul 19, 2026 · 1 min readRead