Notes

Condensed insights from ongoing work. Signal, not noise.
2026-09 · Compliance

A change only counts once it is secured

What can a monitoring system promise a customer who is subject to audits? We examined our own capture path the way an auditor would — and turned the result into a promise that can be checked. Including what the examination found.

2026-08 · Engineering

Publishing a null result — and correcting one of our own figures

Xommodo is complete and the final report is out: no candidate survived the pre-registered criterion. While re-running the numbers we found that a figure published here in August was wrong — and why a tamper-evident chain could carry it anyway.

2026-07 · Cybersecurity

Vulnerability validation: why a failed attempt is no proof of security

A failed exploit attempt does not establish the absence of a vulnerability. Why sound validation needs four verdict classes instead of a yes/no — with examples reproduced in the lab and a traceable evidence log.

2026-07 · Engineering

Xommodo: a track record that proves itself

Progress log of our forecasting research demo: quantile forecasts for commodity prices, committed before the outcome is known — with a hash-chain ledger and OpenTimestamps anchors on the Bitcoin blockchain. Update 08/2026: research concluded — the ledger remains verifiable as a public archive, the results appear as a paper.

2026-07 · Engineering

Tamper-evident audit logs without a server farm

How a SHA-256 hash chain over append-only JSONL makes every retrospective change, deletion or reordering of log entries detectable — and why the deliberately documented limit of the design is a gain for any compliance team.