← All posts

2026-05-09 · 2 min read

Welcome to the secaudit blog

A short note on what to expect here.

We started secaudit because penetration testing — the actual workflow of getting a test scoped, executed, and turned into a useful report — felt stuck in the mid-2010s. Long lead times. PDFs that nobody opens. Findings written for auditors, not for engineers.

This blog is the public side of how we are trying to fix that. Expect:

  • Methodology notes — how we cover OWASP-aligned territory in a way that is repeatable and auditable.
  • Sanitised writeups — interesting bugs from engagements, published only with client permission and full sanitisation.
  • Field notes — patterns we keep seeing across web, API, mobile, and external infrastructure.
  • The occasional rant — when a finding makes us go “again, really?”

We will not flood your feed. Expect roughly one post a month. Subscribe via RSS (coming soon) or just drop back in.

If you have a topic you want us to cover — particularly methodology questions — ask us.