Healthcare Bug Bounties Should Start Before a Breach
The Medyc incident shows why medical software vendors need a safe disclosure route and a funded bug bounty before someone exploits a reportable flaw.
Ernest Bursa
Founder
Notes on hiring, security, and how we build Kit.
The Medyc incident shows why medical software vendors need a safe disclosure route and a funded bug bounty before someone exploits a reportable flaw.
Ernest Bursa
Founder
How to hire a Rails engineer for a startup: define the work, test a safe change in a real-looking app, and score judgment when AI can write the code.
Use this AI agent security incident triage guide to preserve probe evidence, verify application access, contain exposure, and contact the right operator.
Make recruiting messages clear and accountable when AI helps draft. Use this review guide for job ads, outreach, process updates, and rejection notes.
Use this SSO offboarding checklist to test existing sessions, API tokens, directory delays, and exceptions before accepting a SaaS vendor's access controls.
Close a leaked credential report with evidence: remove exposure, invalidate the old secret, prevent recurrence, and document the limits of your impact review.
Build a senior engineer design review interview with a shared proposal, concrete scoring criteria, and consistent questions. Includes a fictional exercise.
Measure AI agent pilot costs per accepted outcome, including retries, human review and unfinished work. A practical worksheet for startup founders.
Define security scanning scope before testing. Check asset ownership, third-party permissions, scanner targets, and who can stop an assessment that goes wrong.
Give recruiting outreach a shared owner, contact state, and stop rules so a second recruiter cannot restart a conversation your candidate already declined.
Displaying items 1-9 of 186 in total