2026-05-09 · 2 min read
Welcome to the secaudit blog
A short note on what to expect here.
We started secaudit because penetration testing — the actual workflow of getting a test scoped, executed, and turned into a useful report — felt stuck in the mid-2010s. Long lead times. PDFs that nobody opens. Findings written for auditors, not for engineers.
This blog is the public side of how we are trying to fix that. Expect:
- Methodology notes — how we cover OWASP-aligned territory in a way that is repeatable and auditable.
- Sanitised writeups — interesting bugs from engagements, published only with client permission and full sanitisation.
- Field notes — patterns we keep seeing across web, API, mobile, and external infrastructure.
- The occasional rant — when a finding makes us go “again, really?”
We will not flood your feed. Expect roughly one post a month. Subscribe via RSS (coming soon) or just drop back in.
If you have a topic you want us to cover — particularly methodology questions — ask us.