About

I'm Herman Errico. I build security products, work with AI agents daily, and spend most of my time in the gap between what vendors say their controls do and what actually happens at runtime.

I started this site because I kept running into the same problem. The security content that exists is marketing dressed up as research, or an academic paper that takes forty pages to reach the one detail you actually needed. When I wanted to understand how a watermark worked, how an agent could be hijacked mid-session, or what a specific malware family did on disk, I ended up piecing it together from five sources, and none of them gave me the interactive, hands-on version that would actually make it stick.

Every article here goes straight to the mechanism and shows real examples: token heatmaps, annotated code, terminal replays, the kind of interactive component that lets you watch something happen instead of reading a paragraph about it. Content is written for people who already know the domain and need the details, the evidence, and the edge cases, not a primer on why the topic matters.

Articles ship when they're done, usually once or twice a month. Subscribe through the form on the homepage if you want them in your inbox. Questions, corrections, or tips: reply to any newsletter email and it reaches me directly.