Journal / company memory
Research, releases, and product thinking.
The Journal is where Top Notchh publishes the evidence behind its products: scan campaigns, product decisions, founder notes, and release thinking.
01 / index
Posts tagged verglos.
J-01
Jul 26, 2026
We Scanned 300 Open Source Repos. Nearly Half Had Critical or High Security Findings.
Verglos scanned 300 public software repositories to understand how AI-era codebases fail. The results validate a new category: security evidence for AI-built software.
9 min read
Read →J-02
Jul 25, 2026
Verglos vs Snyk, GitHub, Semgrep, Socket, and Gitleaks: Why AI-Built Software Needs a Different Security Layer
A founder-friendly comparison of Verglos against top security scanners, and why the wedge is AI provenance, MCP guardrails, and signed evidence.
8 min read
Read →J-03
Jul 24, 2026
The Security Evidence Layer for AI-Built Software
AI-assisted teams do not just need scanners. They need evidence they can show clients, buyers, and auditors. This is the business case for Verglos.
7 min read
Read →J-04
Jul 23, 2026
The Security Bugs AI Code Keeps Writing: 8 Patterns Found Across 300 Repo Scans
Verglos scanned 300 public repositories and found repeated AI-era vulnerability patterns: SQL injection, weak tokens, IDOR, wildcard CORS, stack leaks, secrets, mass assignment, and slopsquat risk.
7 min read
Read →J-05
Jul 19, 2026
How Verglos found a live API key in a 79,000-star repo
GHSA-jhrh-mp85-35j7. The finding, the disclosure, the rotation, and what it says about how AI-era codebases lose credentials — plus what any team can do about it in the next hour.
4 min read
Read →