Blog
Articles on the topics where software initiatives are won or lost.
Field notes
Concrete examples, patterns and experience.
Compliance & provabilityField notes
CRA reporting duty: what your system must deliver within 24 hours
Since 11 September 2026 the Cyber Resilience Act reporting deadlines apply. What the notification requires — and why scattered logs eat the 24 hours.
Compliance & provabilityField notes
Tamper-proof logging: why database logs do not count in an audit
Almost every system logs. Audits still fail on the question of who changed what and when. The difference between a log and evidence — and what creates it.
Compliance & provabilityField notes
Multi-tenancy with Keycloak: what belongs in the token and what doesn't
Multi-tenancy rarely fails at the login screen — it fails at the model behind it. A practical guide to realms, roles, token design and migrating existing users.
Foundation
The underlying stance on this area — why we work the way we do.
Compliance & provabilityFoundation
Tenant separation that survives the security questionnaire
One forgotten filter is a reportable incident. Why isolation in application code is not evidence — and which models enterprise buyers accept.
Notes
Short thoughts, links and videos.
Compliance & provabilityNote
Twelve roles become three: what Gartner's team shapes mean for provability
Gartner expects smaller engineering teams. The role map behind it mostly removes translation roles — and with them the places where decisions used to get written down as a side effect.