Skip to content
TopNotchh.

Journal / company memory

Research, releases, and product thinking.

The Journal is where Top Notchh publishes the evidence behind its products: scan campaigns, product decisions, founder notes, and release thinking.

01 / index

Posts tagged verglos.

J-01

Jul 26, 2026

verglosresearchscan-campaignai-security

We Scanned 300 Open Source Repos. Nearly Half Had Critical or High Security Findings.

Verglos scanned 300 public software repositories to understand how AI-era codebases fail. The results validate a new category: security evidence for AI-built software.

9 min read

Read →

J-02

Jul 25, 2026

vergloscomparisonpositioning

Verglos vs Snyk, GitHub, Semgrep, Socket, and Gitleaks: Why AI-Built Software Needs a Different Security Layer

A founder-friendly comparison of Verglos against top security scanners, and why the wedge is AI provenance, MCP guardrails, and signed evidence.

8 min read

Read →

J-03

Jul 24, 2026

verglosagenciesfoundershandoff

The Security Evidence Layer for AI-Built Software

AI-assisted teams do not just need scanners. They need evidence they can show clients, buyers, and auditors. This is the business case for Verglos.

7 min read

Read →

J-04

Jul 23, 2026

verglosdeveloperpatternsai-security

The Security Bugs AI Code Keeps Writing: 8 Patterns Found Across 300 Repo Scans

Verglos scanned 300 public repositories and found repeated AI-era vulnerability patterns: SQL injection, weak tokens, IDOR, wildcard CORS, stack leaks, secrets, mass assignment, and slopsquat risk.

7 min read

Read →

J-05

Jul 19, 2026

verglosdisclosuresecrets

How Verglos found a live API key in a 79,000-star repo

GHSA-jhrh-mp85-35j7. The finding, the disclosure, the rotation, and what it says about how AI-era codebases lose credentials — plus what any team can do about it in the next hour.

4 min read

Read →