Field notes from the engine room.
Short, opinionated writing on architecture, security, and the craft of shipping software that lasts.
What we've been writing about.
No listicles. No SEO padding. Every post is something we'd hand a client.
RLS is not a feature — it's the floor
Row-level security is the minimum, not the win. Here's how we layer policy, audit, and threat modelling on top so a leaked key is a shrug, not a headline.
Request an early copyThe hidden tax of five vendors
What actually breaks when your design agency, backend shop, and security consultant have never met. A field guide to blame-free architecture.
Request an early copyServer functions killed our OpenAPI spec
Why we stopped writing REST endpoints for internal calls and moved everything to typed RPC — and the two places we still keep a public API.
Request an early copyTokens, not utilities
A minimal semantic token layer beats every ad-hoc Tailwind class. The 40-token contract we use on every project.
Request an early copyCutover playbook: zero downtime, zero heroics
The DNS, database, and observability sequence we run for every launch — including the rollback we've never had to use.
Request an early copyAI belongs in the back office first
Customer-facing AI is glamorous and mostly wrong. Where the real leverage lives — and how we measure it.
Request an early copy