TrustFix Journal

Field notes from the machine-identity frontier.

Research and plain-spoken writing on non-human identity, AI agents, and the supply chain — what is breaking, why your human-IAM stack misses it, and how to prove a fix actually held.

Machine IdentityJun 17, 2026 · 5 min

Certificates are identities too.

Code-signing material is the most dangerous forgotten non-human identity in your estate. It can mint trusted artifacts, it rarely has an owner, and almost no one runs its lifecycle the way they run IAM.

Read
Supply ChainJun 3, 2026 · 7 min

npm is now a worm highway.

Shai-Hulud, the chalk/debug maintainer phishing, and the Nx s1ngularity compromise share a root cause: standing publish tokens that turn one stolen credential into self-propagating supply-chain compromise.

Read
Supply ChainMay 13, 2026 · 7 min

One stolen token, 700 orgs: the OAuth integration blast-radius problem.

The 2025 Salesloft Drift campaign turned a single connected-app compromise into mass data theft across hundreds of downstream tenants. The lesson is to map every integration’s scope and reach before the breach, not after.

Read
Field NotesApr 9, 2026 · 5 min

Detect everything — even what you can’t fix.

A field note on the philosophy underneath the product: visibility first, honesty about limits second, and never the temptation to hide a risk just because we don’t have a clean fix for it.

Read
Proof & TrustMar 4, 2026 · 6 min

Proof you can check without trusting us.

Most security tools ask you to believe their dashboard. TrustFix issues a signed artifact you can verify yourself — offline, against open standards, with zero access to us. It keeps verifying even if we disappear.

Read
Machine IdentityFeb 11, 2026 · 6 min

Your org has more non-human identities than employees — and no one owns them.

CI/CD tokens, OAuth apps, IAM keys, service accounts, signing certificates, MCP servers, AI agents. The fastest-growing attack surface of 2026 is the one your IAM team was never asked to manage.

Read
Blog | TrustFix