Services
About
Blog
Contact
+1 (415) 555-0142
Get a quote →
THE JOURNAL
Notes on building, shipping & securing the web.
FEATURED · AI
How we shipped a support agent that resolves 62% of tickets
The architecture, evals and guardrails behind a production AI agent — and the three mistakes we made first.
Daniel Reyes
Sep 18, 2026 · 5 min read
All
AI
WordPress
Shopify
Performance
Security
SEO
E-commerce
Design
DevOps
Engineering
Security · 6 min
The WordPress security baseline we apply to every site
Twelve controls that stop the vast majority of attacks we see in our care plans.
Maya Okafor
· Jul 15, 2026
Security · 5 min
GDPR for website owners: the security side most teams miss
Cookie banners get the attention, but GDPR also expects appropriate security, data minimization and a breach plan. What that means in practice.
Maya Okafor
· Apr 21, 2026
Security · 5 min
Uptime monitoring that catches real problems without alert fatigue
A monitor that pages you for every blip gets muted within a month. How we choose checks, thresholds and escalation paths that stay trusted.
Leo Tanaka
· Feb 10, 2026
Security · 5 min
Secrets management for small web teams
API keys in repositories and passwords in chat threads are how many breaches start. A lightweight approach that fits a team of five.
Leo Tanaka
· Dec 16, 2025
Security · 5 min
Admin access hygiene: two-factor, roles and offboarding
Stolen and forgotten accounts cause more breaches than exotic exploits. A practical process for who gets access, how, and for how long.
Maya Okafor
· Oct 21, 2025
Security · 5 min
Penetration test or security audit: which one you actually need
They are often sold interchangeably, but they answer different questions. How to choose, scope and budget for each.
Maya Okafor
· Aug 26, 2025
Security · 5 min
What a web application firewall does, and what it will not do
A WAF blocks a large share of automated attacks, but it is not a substitute for patching. How we configure one without breaking the site.
Leo Tanaka
· Jul 01, 2025
Security · 5 min
Backups that actually restore: how we design and test them
Most backup plans are never tested until the day they fail. Here is how we set retention, storage and quarterly restore drills.
Leo Tanaka
· May 06, 2025
Security · 5 min
How we vet a WordPress plugin before it reaches production
Plugins are the largest attack surface on most WordPress sites. This is the review we run before any new one is installed.
Maya Okafor
· Mar 11, 2025
Security · 5 min
The first hour after your website is hacked
A calm, ordered response plan for the moment you discover a compromise, from containment and evidence to cleanup and communication.
Leo Tanaka
· Jan 14, 2025
One email a month. Only the good stuff.
Field notes from real client projects. No spam.
Subscribe