Trust, documented

Editorial policy

The process behind every article on this site. If we ever fail it, tell us — the contact page is the complaints department.

How content is researched

Articles are written from primary sources: official specifications (IETF RFCs, W3C, WHATWG), vendor documentation (MDN, browser security teams), recognized bodies of practice (OWASP, NIST, CISA), and peer-reviewed research. Secondary blogs and news coverage may inspire a topic but never serve as the factual basis for a claim. Every article lists its sources in a dedicated section at the end.

How content is reviewed

Every article carries a named author whose credentials and expertise are public on their author page. Before publication, technical claims are checked against the cited sources, every code sample is run, and defensive guidance is verified against current best practice — not what was true five years ago. Corrections raised after publication are treated as first-class work, not afterthoughts.

How content is updated

Security ages fast. Every page shows both its original publication date and its last substantive update in the byline, backed by machine-readable dates in the page metadata and sitemap. When a browser change, deprecation, or new attack technique invalidates guidance, we revise the article rather than publishing a contradicting one — the URL is the reference, and the reference stays current.

The ethical boundary

We teach mechanisms and defenses, and we cover offensive concepts the way good textbooks do: enough to understand, detect, and prevent. We do not publish step-by-step instructions for attacking systems you do not own, and every practice recommendation on this site points to legal targets — your own lab, deliberately vulnerable training environments, or authorized programs. This line is not negotiable, including for advertisers or sponsors, of which we currently have none.

AI assistance disclosure

Drafting and editing tools, including AI assistants, may be used in production. Every technical claim is still verified by the named author against primary sources before publication, and the author is accountable for the result. Nothing ships on autopilot.

Corrections

Factual errors are corrected in place, with an update to the revision date. Substantive corrections that change a recommendation are noted in the article body. To report an error, use the contact page — corrections get priority handling.