Research
Notes and research.
Notes on infrastructure, the tools we build, and the security research behind them.
June 24, 2026
The S3 misconfiguration we keep finding in 2026
Public buckets are mostly solved. The access we keep finding now is quieter: over-broad IAM conditions, forgotten replication rules, and presigned URLs that outlive their purpose.
Read article →May 12, 2026
SOC 2 for a 15-person startup: a pragmatic path
You do not need a GRC platform, a policy binder, or a compliance hire. You need scoped controls, evidence that collects itself, and about a quarter of calendar time.
Read article →April 7, 2026
Why your pentest report shouldn't be a PDF graveyard
Most pentest findings die in a PDF nobody opens twice. The fix is structural: findings as tickets, severity in context, and a retest baked into the engagement.
Read article →March 3, 2026
Zero trust without the vendor bingo
Zero trust is four architectural decisions, not a product category. Here is the version you can build with the identity provider and cloud primitives you already pay for.
Read article →May 22, 2024
The Silent Threat: Data Exfiltration via RAG
How an attacker can use indirect prompt injection to force your enterprise RAG system to exfiltrate confidential documents.
Read article →April 12, 2024
The boundaries of model trust in security automation
Why deploying an LLM into a security workflow without a harness is a recipe for silent failure, and how to verify output before shipping.
Read article →Want to try Casefile?
Join the waitlist. We will email you when early access opens.