→ Field notes

The honest playbook for SaaS security and compliance.

13 articles on what we've learned shipping pen tests, SOC 2 readiness programs, and continuous scans for SaaS teams. No vendor marketing. Concrete patterns, real numbers, opinionated advice.

All articles

May 30, 2026

What a pen test actually costs in 2026

A real breakdown of pen-test pricing, what drives the variance from $3K to $50K, and how to tell whether a quote is honest before you spend a dollar.

9 MIN →
May 30, 2026

IDOR: the bug class that keeps killing SaaS startups

Broken object-level authorization is the most common critical finding in SaaS pen tests in 2026. Here's why it happens, how to find it, and the patterns that fix it for good.

8 MIN →
May 30, 2026

Security questionnaire survival guide: 300 questions, 30 hours of your life

How to answer enterprise security questionnaires in a fraction of the time, what to never answer, and the trust-center pattern that makes 80% of them disappear.

7 MIN →
May 29, 2026

SOC 2 Type I vs Type II: which one your customers actually want

The real difference between Type I and Type II, what each costs, which one unblocks which kind of deal, and the order that actually works for early-stage SaaS.

8 MIN →
May 28, 2026

Five scoping mistakes that double your pen-test bill

How buyers accidentally inflate pen-test cost during the scoping call — and the simple corrections that bring quotes back to reality.

7 MIN →
May 28, 2026

What goes in the auditor's evidence binder (and what doesn't)

The exact artifact list a SOC 2 Type II auditor expects, organized by Trust Service Criterion, with the format and frequency that satisfies the request first-time.

6 MIN →
May 27, 2026

The SOC 2 controls that actually move the needle (and the ones that don't)

Trust Services Criteria boil down to about 12 controls auditors really care about. Here's what they look for and what's mostly ceremony.

7 MIN →
May 26, 2026

Automated vs. human pen test: an honest breakdown

Where automation actually matches a human pen tester, where it doesn't, and how the modern hybrid model splits the work — with examples of findings each side actually catches.

8 MIN →
May 26, 2026

DPA, MSA, NDA, SoW: when each one actually matters

Four pieces of paper SaaS founders accumulate without understanding. Here's what each does, when you need it, and how to make the signing actually happen fast.

6 MIN →
May 25, 2026

Security headers cheat sheet for 2026

What each security header actually does, what value to set, and why most CSP rollouts fail (and how to do it without breaking the site).

6 MIN →
May 24, 2026

Vanta vs Drata vs Secureframe in 2026: honest comparison

All three do the same job, all three cost $7-15K/year. Here's how they actually differ in practice, after watching dozens of customers run them.

7 MIN →
May 23, 2026

Handing off to your CPA auditor: what they want you to do (and not do)

A practical guide to the auditor handoff. What information to share before kickoff, what surprises blow up audit timelines, and how to keep the engagement moving.

5 MIN →
May 22, 2026

A working dependency-CVE strategy that doesn't drown your team

How to triage dependency vulnerabilities so you fix what actually matters, ignore what doesn't, and stop your security backlog from drowning the team.

6 MIN →