Engineering Blog

Notes from building VulneraX

We write about what actually happened, including the bugs — not just the launches.

2026-07-14

Closing the last live critical vulnerabilities before beta

A cross-tenant SOC event forgery bug, a billing webhook that failed open, and fabricated EASM discovery data — all found, fixed, and live-verified in one pass.

2026-07-09

What "controlled paid beta" actually means for us

Why we scored our own launch readiness at 95/100 and still didn’t call it a public launch — and what closed the gap from our previous pass.

2026-07-08

Finding zero real persistence in two services, months after launch

DFIR and threat-intel data was living entirely in process memory despite fully-built ORM models sitting unused. Here’s how an adversarial internal review caught it.

2026-07-07

The JWT secret that shipped as a placeholder

A real, live-confirmed incident: the platform-wide signing secret was running in production as the literal string used in local dev examples. What we changed so it can’t happen silently again.