← all research
2026-07-07research

Introducing Pagesync Research

What we'll publish here: engagement-driven writeups, security advisories, and notes from building secure software.

#meta

Security work generates knowledge, and knowledge locked in private reports helps exactly one company at a time. This page is where we publish the parts that help everyone else.

What to expect

Three kinds of posts will show up here:

  • Research — technical writeups from our own work: patterns we keep seeing in assessments, tooling notes, and deep dives into classes of vulnerabilities. Client details never appear; lessons do.
  • Advisories — coordinated disclosures for vulnerabilities we find in third-party software, published after vendors have had a fair window to fix. Each advisory carries a severity, affected versions, and a disclosure timeline.
  • Build notes — how we build our own systems securely. We hold ourselves to the standards we audit against, and we'd rather show that than claim it.

Disclosure policy

If you're a vendor and we've contacted you about a vulnerability: our default window is 90 days from first contact, extended when a fix is genuinely in progress. If you've found an issue in our systems, see security.txt — we appreciate the report and won't be weird about it.

Following along

There's an RSS feed. No newsletter, no tracking — just the feed.

Work with us

This is the kind of thinking we bring to engagements. Start a project →