FREESanctions, PEP & AML/CFT screening database. Search any name.
Research

White papers for the people who carry the risk

One idea runs under all of them: detection is cheap and getting cheaper, and trust is not. Anyone can generate a finding, an alert, or a block. Being able to prove it, and being honest about what you cannot, is the whole job. Problems worth your time, each written for a real reader and mapped to how we approach it.

New · Data report
The State of App Security in African Finance
We passively scanned 618 public apps across 347 African banks, fintechs, payment companies, crypto exchanges and insurers. 50% grade C or below, and the banks and fintechs are each half-secure in opposite ways. Aggregate only, no institution named.
Read the report →
Interactive · Field guide
Can your WAF stop this?
Twelve attacks a signature WAF and your own code both miss, from a direct PostgREST table dump and a Next.js middleware auth bypass to IDOR and same-day zero-days. Each ships with a curl you can run against an app you own, then watch positive security catch it.
Open the field guide →
RedSecurity leaders

Four Hundred Findings, Zero Trust

The verification problem in AI security testing, and what to demand instead.

Read · 6 min →
ShieldAppSec & platform teams

After RASP

Why runtime application defense keeps failing, and what the successor has to do differently.

Read · 6 min →
BlueCISO & IT operations

Your Security Agent Is Now Your Biggest Outage Risk

The availability cost of endpoint security, and the case for a driverless design.

Read · 6 min →
ForgeProduct security & maintainers

Machines Are Finding Zero-Days. Can You Trust Them?

Autonomous bug discovery has arrived. The bottleneck moved from finding to proving.

Read · 6 min →
Red · LLMDevelopers & AppSec

The Untested Surface

You shipped an AI feature last quarter. Who is testing it like an attacker?

Read · 7 min →
ShieldDevelopers & API teams

The Attacks Your WAF Was Never Built to See

Business-logic abuse, broken object access, and the case for learning your app's own normal.

Read · 6 min →
RedDevelopers & DevSecOps

Your AI Assistant Is Writing Your Next Breach

Slopsquatting: when the coding model invents a package name, and an attacker registers it.

Read · 6 min →
Red · ForgeBuyers & security leaders

The Pentest PDF Is a Trust Problem

Why security findings should carry their own proof, and what that changes for buyers.

Read · 6 min →
ShieldAI platform teams

Guardrails Aren't a Security Control

Why AI applications need a learned behavioral envelope at the model boundary, not a keyword filter.

Read · 6 min →
BlueCISO & business

Assume Detection Fails

The recovery backstop for ransomware, and why rollback beats faster alerts.

Read · 6 min →
Shield · Get startedDevelopers & AppSec

Protect an App in Two Minutes

One line of code turns “this app only ever behaves in these ways” into an enforced rule, in any language.

Read · 5 min →
Shield · BrowserE-commerce & payments

Guard the Checkout Your Server Never Sees

A skimmer runs in the browser and steals the card before it reaches your server. No backend tool sees it. Here's the two-minute fix.

Read · 5 min →
Shield · LLMAI platform teams

Put a Learned Boundary Around Your AI Feature

Guardrails are a keyword filter. Your LLM app needs a learned behavioral envelope, installable in two minutes.

Read · 5 min →
Shield · APIAPI & platform teams

See Every API You Have, Including the Ones You Forgot

Discovery, sensitivity mapping, and BOLA protection for every endpoint, learned from real traffic in two minutes.

Read · 5 min →
Positive SecurityFinancial institutions & security leaders

You Can't Blocklist What Doesn't Exist Yet

AI generates novel attacks faster than any signature can be written. The only defense that scales is learning what your systems are supposed to do, and refusing the rest.

Read · 14 min →
DDoS MitigationPlatform & security engineers

Two Routes to a Dead Server

L3/L4 DDoS is a physics problem before a security one. Nemesis filters in two places at once, the DNS edge and the server's own kernel (XDP), and this is an honest tour of both, including where a global anycast network still wins.

Read · 9 min →
ComplianceBanks, fintechs & regulators

Compliance Became Infrastructure

Nigeria came off the FATF grey list, then the CBN spent 2026 turning effectiveness into mandatory, real-time rules.

Read · 5 min →
FraudFraud & risk teams

Down 51%, Up 603%: The Nigerian Fraud Paradox

NIBSS says fraud fell 51 percent. FITC says bank fraud loss rose 603 percent. Both are true, and the reason is the whole story.

Read · 4 min →
Real-time FraudPayments & fraud teams

A Quadrillion Naira, In Real Time

Nigeria's rails move over a quadrillion naira a year. At settlement speed, any control that is not real time is defending yesterday.

Read · 4 min →
Insider RiskFraud, risk & compliance

The Insider Quarter

FITC logged 63 staff fraud cases in a single quarter. Why 'we authenticated it' is no longer a defence.

Read · 4 min →
MarketExecutives & risk leaders

The Whole System Is Recapitalising

Banks, insurers and pensions are all being forced to get bigger at once. Bigger institutions are bigger targets.

Read · 5 min →
ComplianceCompliance & risk teams

Fraud Is Now on the Public Record

Fraud now goes to the National Assembly every quarter. Auditability just became a competitive advantage.

Read · 4 min →
Thought LeadershipFounders, executives & regulators

Nigeria Wants to Set Africa's Fintech Rules

Nigeria wants to set the standard for African fintech. Standards live in enforcement, not circulars.

Read · 4 min →
Autogon ResearchBanks, fintechs & regulators

The State of App Security in African Finance

We passively scanned 618 public apps across 347 African financial institutions. Here is what the internet already knows.

Read · 6 min →