Field notes
Practical write-ups on migrating off no-code builders, securing AI-written code, and shipping products that last.
Aug 2, 2026 · 10 min read
Every Supabase key, what it does, and which ones can be public
The legacy keys are being retired, and they can no longer be rotated. Here is what replaces them, and how to tell which one you shipped.
ReadJul 27, 2026 · 5 min read
What Bubble's Security Dashboard won't fix for you
Bubble's Security Dashboard flags missing privacy rules. Learn what it cannot fix and why a green dashboard may still leave data exposed.
ReadJul 26, 2026 · 7 min read
What goes wrong inside Framer code components
What can go wrong in Framer code components: exposed API keys, untrusted imports and content turned into executable markup.
ReadJul 6, 2026 · 5 min read
Auditing an app built to be insecure
A walkthrough of a deliberately vulnerable app: exposed secrets, an open user list, broken access control and findings scanners miss.
ReadJun 30, 2026 · 9 min read
The security holes in AI-built apps
The access-control flaws, exposed secrets and misconfigurations found most often in apps built on Lovable, Base44 and Replit.
Read
Get them in your inbox
Be the first to read each field note. No noise, just the good stuff.
