Field notes from the machine-identity frontier.
Research and plain-spoken writing on non-human identity, AI agents, and the supply chain — what is breaking, why your human-IAM stack misses it, and how to prove a fix actually held.
Certificates are identities too.
Code-signing material is the most dangerous forgotten non-human identity in your estate. It can mint trusted artifacts, it rarely has an owner, and almost no one runs its lifecycle the way they run IAM.
Readnpm is now a worm highway.
Shai-Hulud, the chalk/debug maintainer phishing, and the Nx s1ngularity compromise share a root cause: standing publish tokens that turn one stolen credential into self-propagating supply-chain compromise.
ReadOne stolen token, 700 orgs: the OAuth integration blast-radius problem.
The 2025 Salesloft Drift campaign turned a single connected-app compromise into mass data theft across hundreds of downstream tenants. The lesson is to map every integration’s scope and reach before the breach, not after.
ReadDetect everything — even what you can’t fix.
A field note on the philosophy underneath the product: visibility first, honesty about limits second, and never the temptation to hide a risk just because we don’t have a clean fix for it.
ReadProof you can check without trusting us.
Most security tools ask you to believe their dashboard. TrustFix issues a signed artifact you can verify yourself — offline, against open standards, with zero access to us. It keeps verifying even if we disappear.
ReadYour org has more non-human identities than employees — and no one owns them.
CI/CD tokens, OAuth apps, IAM keys, service accounts, signing certificates, MCP servers, AI agents. The fastest-growing attack surface of 2026 is the one your IAM team was never asked to manage.
Read