Security and AI, shown rather than described
Interactive pages that run entirely in your browser. Each one follows a real thing step by step, then shows where it gets attacked and what a company has to prove about it. No sign-up, no tracking, nothing you type leaves the page.
How your authenticator app works
Follow one six-digit code from shared secret to digits, live, with a QR you can scan into your own app.
RFC 6238, live in your browser →AuthenticationHow a passkey signs you in
A real key pair, a real signature, a real verification, byte by byte. Switch the origin and watch phishing fail.
WebAuthn, live in your browser →SecurityThe life of a secret
Five stages from creation to revocation. How each is attacked, what you do, and what a company must prove.
Attack, individual and corporate lanes →AI and controlsAn AI agent inside a business process
Pick a process and an autonomy level, run a normal and a poisoned request, see every control gate fire.
Simulation, maps to SOC 2 and ISO 27001 →AI and controlsHow an AI agent gets prompt-injected
The same request with a hidden instruction in a PDF, an email, a web page, a code comment. Toggle four defences.
Rule simulator →AI and controlsLeast privilege, visualised
A permission matrix for a small company. Click a role, see the blast radius if it leaks. Add an agent as a row.
Interactive matrix →We build the systems and we sit on the audit side of the table. These pages are how we explain both halves to the people who have to live with them.