Writing

Notes from building Umbra.

Cloud security posture, done the Umbra way: proof, paths, and the fix

We shipped read-only cloud posture across AWS, Google Cloud, and Azure. It's not another wall of misconfigurations. It proves exposure with an anonymous read, chains findings into paths that terminate at your data, and hands you the exact command to fix each one.

We built Umbra in the open. Here's why.

A short note on why an external attack-surface tool ships with public docs, transparent pricing, and an open architecture.