Security research notes, tooling, and writeups from someone who reads RFCs for fun.
Fast CLI for auditing security headers across a domain list.
Static analysis for common JWT implementation mistakes.
Diffing tool for tracking unexpected DNS and cert changes.