Introducing Pagesync Research
What we'll publish here: engagement-driven writeups, security advisories, and notes from building secure software.
#meta
Security work generates knowledge, and knowledge locked in private reports helps exactly one company at a time. This page is where we publish the parts that help everyone else.
What to expect
Three kinds of posts will show up here:
- Research — technical writeups from our own work: patterns we keep seeing in assessments, tooling notes, and deep dives into classes of vulnerabilities. Client details never appear; lessons do.
- Advisories — coordinated disclosures for vulnerabilities we find in third-party software, published after vendors have had a fair window to fix. Each advisory carries a severity, affected versions, and a disclosure timeline.
- Build notes — how we build our own systems securely. We hold ourselves to the standards we audit against, and we'd rather show that than claim it.
Disclosure policy
If you're a vendor and we've contacted you about a vulnerability: our default window is 90 days from first contact, extended when a fix is genuinely in progress. If you've found an issue in our systems, see security.txt — we appreciate the report and won't be weird about it.
Following along
There's an RSS feed. No newsletter, no tracking — just the feed.
Work with us
This is the kind of thinking we bring to engagements. Start a project →