Journal
Field Notes
Notes from secure code review and hardening work—techniques, decisions, and cautionary patterns.
How we scope a secure code review without boiling the ocean
A practical way to draw module boundaries so findings stay actionable before a release date.
Read the noteCookie flags and session fixation: what we still find in 2026
Session handling mistakes that keep appearing in application hardening advisory sessions across Thailand product teams.
Read the noteWriting remediation notes engineers will actually pick up
How System Stonepoint structures findings so secure code review items become sprint tickets instead of unread PDFs.
Read the notePreparing a pre-release security gate in seven days or fewer
A field checklist for teams booking a go/hold review when the calendar will not move.
Read the note