About

I'm Herman Errico. I build security products, work with AI agents daily, and spend most of my time in the gap between what vendors say their controls do and what actually happens at runtime.

I started this site because I kept running into the same problem: the security content that exists is either marketing dressed up as research, or academic papers that take forty pages to reach the one detail you need. When I wanted to understand how a watermark worked, how an agent could be hijacked mid-session, or what a specific malware family actually did on disk, I had to piece it together from five sources, none of which gave me the interactive, hands-on version that would make it stick.

Just Security is what I wanted to find and couldn't. Every article goes straight to the mechanism, shows real examples, and uses interactive components (token heatmaps, annotated code, terminal replays) so you can see how something works rather than just reading a description of it. No filler, no marketing language, no twenty-paragraph buildup before the actual finding. Practical content for busy people who need to understand the details, not just the category.

Articles ship when they're done. If you want them in your inbox, subscribe through the form on the homepage. Questions, corrections, or tips: reply to any email from the newsletter and it reaches me directly.