the adversarial audit

It isn't one audit. It's a discipline.

Anyone can run a security pass once and screenshot the green. The harder thing is to keep re-attacking your own system as it grows — and get the same answer every time. The latest round: a 50-agent audit, its fixes shipped, then a separate 14-lens adversarial re-audit where every finding had to survive a skeptic before it counted. What holds, holds.

the cadence

Re-attacked, round after round — and the core never broke.

latest
14-lens re-audit of the last remediation — residual-bypass + regression hunt per fix, each finding refuted by an independent agent. 2 low edge-cases survived, both fixed; nothing cross-tenant, no money or governance break.
before it
50-agent audit → a minimal 9-PR remediation across the store seams (calendar, channels, the autonomous resident, the tenant economy, GDPR/PECR) — all shipped, tested, redeployed.
before that
44-agent audit — 9 findings, 3 high (incl. a cross-tenant conversation leak) — all fixed; and a 30-agent extension analysis that surfaced real bugs as a side-effect of grounding.
and earlier
whole-platform and whole-Studio adversarial passes, the flagship, and several before them — a running trail in git.

✓ crown jewels held every round — isolation · money · governance · SSRF · token domains

three of the real ones

HIGH Cross-tenant conversation leak

Chat memory was keyed by the sender, not the tenant — so a guest who messaged two businesses through the platform could have one's conversation surface inside the other's prompt. Fixed: memory is tenant-keyed at the storage layer, so a shared sender physically can't cross the boundary.

HIGH A provider draining a caller

In the cross-tenant tool economy, a provider could raise the price of a granted tool after a caller began using it and drain their balance. Fixed: the caller consents to a price per call, fail-closed — no consent, no charge — enforced before a single credit moves.

HIGH Crisis behind the meter

The billing check ran before the crisis check, so a distressed customer messaging an out-of-credits business got "unavailable" instead of a crisis line. Fixed: crisis is served free, ahead of every ceiling and charge, on every customer surface.

The lenses span isolation · auth · injection · money · governance · booking · channels · the autonomous resident · data-rights (GDPR/PECR) · the site generator · frontend · ops. Verdict, every round: zero critical standing; tenant isolation and the XSS surface came back clean; no live auth bypass — every confirmed edge fixed and redeployed.

the honest numbers

Every number, with the asterisk already attached.

Most builders pad. I'd rather you trust the parts that are real than be impressed by parts that aren't.

1builder* not a team
1,455tests green* not a formal proof
6 → 0audits · criticals standing* self-run, not third-party
0cross-tenant breaches, ever* the one line that has to hold — and has
1production instance* by choice — scale isn't the lesson yet

The system is honest because the person who designed it is. I made sure of that from the start — built in, not bolted on.

the invitation

The numbers hold. Asterisks included.

If you want a builder who attacks his own work this hard before anyone asks — and keeps doing it as the system grows — let's talk.