<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Security Architects, Inc on Security Architects</title>
		<link>https://securityarchitects.com/</link>
		<description>Recent content in Security Architects, Inc on Security Architects</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
		
		
		
			<lastBuildDate>Tue, 21 Jul 2026 09:00:00 -0700</lastBuildDate>
		
			<atom:link href="https://securityarchitects.com/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Authinator3</title>
				<link>https://securityarchitects.com/products/authinator/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://securityarchitects.com/products/authinator/</guid>
				<description>&lt;img src=&#34;https://securityarchitects.com/images/logo/authinator.svg&#34; alt=&#34;&#34; class=&#34;product-mark&#34;&gt;&#xA;&lt;p&gt;&lt;strong&gt;Authinator&lt;/strong&gt; is a web login gateway for firewalls: authenticate over HTTPS,&#xA;click once, and your current IP address is granted passage through the&#xA;firewall. Everyone else sees a wall.&lt;/p&gt;&#xA;&lt;p&gt;It solves the classic remote-access dilemma. Leaving management ports (SSH,&#xA;VPN, admin panels) open to the internet invites the whole world to knock;&#xA;port-knocking schemes are brittle and awkward to use from a phone or a&#xA;borrowed machine. Authinator replaces both with something anyone can operate:&#xA;a login page.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Claudette</title>
				<link>https://securityarchitects.com/products/claudette/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://securityarchitects.com/products/claudette/</guid>
				<description>&lt;img src=&#34;https://securityarchitects.com/images/logo/claudette.svg&#34; alt=&#34;&#34; class=&#34;product-mark&#34;&gt;&#xA;&lt;p&gt;&lt;strong&gt;Claudette&lt;/strong&gt; is a sandbox for running AI coding agents — like Claude Code —&#xA;safely on your own machine. AI agents read web pages, READMEs, issue threads,&#xA;and email while wielding real tools: your shell, your git credentials, your&#xA;network. Claudette puts a security boundary around all of that, so an agent&#xA;doing useful work can&amp;rsquo;t be turned into a liability by the untrusted content&#xA;it reads.&lt;/p&gt;&#xA;&lt;p&gt;It isn&amp;rsquo;t a research prototype. It&amp;rsquo;s the sandbox Security Architects uses to&#xA;run AI coding agents in production, every day — including the work behind this&#xA;very website.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Cone of Silence</title>
				<link>https://securityarchitects.com/products/cone-of-silence/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://securityarchitects.com/products/cone-of-silence/</guid>
				<description>&lt;img src=&#34;https://securityarchitects.com/images/logo/cone-of-silence.svg&#34; alt=&#34;&#34; class=&#34;product-mark&#34;&gt;&#xA;&lt;p&gt;&lt;strong&gt;Cone of Silence&lt;/strong&gt; is our agent-pod service: your own always-on AI agent —&#xA;Claude, working for you around the clock — running inside a hardened sandbox&#xA;on a dedicated pod, reachable from your phone over Telegram. Message it like a person; it reads,&#xA;researches, codes, and runs real tools — while everything it touches stays&#xA;inside a security boundary we built and operate.&lt;/p&gt;&#xA;&lt;p&gt;Always-on agents are the most exciting — and most exposed — thing happening&#xA;in computing right now. Internet-wide scans this year found &lt;strong&gt;tens of&#xA;thousands of personal AI agents running openly exposed&lt;/strong&gt;, unsandboxed, with&#xA;full access to their owners&amp;rsquo; machines and credentials. The ecosystem&amp;rsquo;s&#xA;defaults are convenience-first. Ours are not.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Truepost</title>
				<link>https://securityarchitects.com/products/truepost/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://securityarchitects.com/products/truepost/</guid>
				<description>&lt;img src=&#34;https://securityarchitects.com/images/logo/truepost.svg&#34; alt=&#34;&#34; class=&#34;product-mark&#34;&gt;&#xA;&lt;p&gt;&lt;strong&gt;Truepost&lt;/strong&gt; is an email client that finally feels like the messaging apps&#xA;you actually enjoy using: conversations grouped by &lt;em&gt;people&lt;/em&gt;, chat-style&#xA;bubbles, one composer — no more digging through stacked threads to find the&#xA;latest reply. It works with the email you already have: &lt;strong&gt;Gmail, Yahoo, and&#xA;Outlook&lt;/strong&gt;, connected via OAuth2 and IMAP.&lt;/p&gt;&#xA;&lt;h2 id=&#34;trust-you-can-see&#34;&gt;Trust you can see&lt;/h2&gt;&#xA;&lt;p&gt;Truepost treats sender identity as a security surface, not a cosmetic one:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;The address is the identity; the display name is just a claim.&lt;/strong&gt; A&#xA;spoofer sending &lt;code&gt;From: &amp;quot;Your Bank&amp;quot; &amp;lt;evil@attacker.example&amp;gt;&lt;/code&gt; gets a badge&#xA;and identity derived from the &lt;em&gt;address&lt;/em&gt; — the claimed name can never&#xA;impersonate its way into the avatar.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Reputation-tinted sender tiles&lt;/strong&gt; put a visible trust signal on every&#xA;conversation — something mainstream clients simply don&amp;rsquo;t show.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;One-click block and report.&lt;/strong&gt; Senders you don&amp;rsquo;t want hearing from are&#xA;gone in a tap.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;privacy-first&#34;&gt;Privacy-first&lt;/h2&gt;&#xA;&lt;p&gt;Your mail stays yours: no server-side scanning, no selling data, no&#xA;training models on your inbox. Optional end-to-end encryption between&#xA;Truepost users is on the roadmap.&lt;/p&gt;</description>
			</item>
			<item>
				<title>1lan</title>
				<link>https://securityarchitects.com/products/1lan/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://securityarchitects.com/products/1lan/</guid>
				<description>&lt;img src=&#34;https://securityarchitects.com/images/logo/1lan.svg&#34; alt=&#34;&#34; class=&#34;product-mark&#34;&gt;&#xA;&lt;p&gt;&lt;strong&gt;1lan&lt;/strong&gt; (&amp;ldquo;One LAN&amp;rdquo;) makes machines stuck behind NAT and firewalls reachable&#xA;again — home servers, lab boxes, appliances in the field — by having each one&#xA;dial home with a persistent reverse SSH tunnel to a relay server you own.&#xA;Once connected, every client is one SSH command away, and selected service&#xA;ports (web UIs, media servers, APIs) are reachable through the relay&amp;rsquo;s&#xA;hardened HTTPS front end.&lt;/p&gt;&#xA;&lt;p&gt;It&amp;rsquo;s the self-hosted answer to commercial tunnel and overlay services: no&#xA;third-party relay in your traffic path, no proprietary agent, no subscription.&#xA;The moving parts are deliberately boring — &lt;strong&gt;plain OpenSSH, a shell script,&#xA;and a systemd unit&lt;/strong&gt; — because boring is auditable.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Ozone (Legacy)</title>
				<link>https://securityarchitects.com/products/ozone/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://securityarchitects.com/products/ozone/</guid>
				<description>&lt;img src=&#34;https://securityarchitects.com/images/logo/ozone.svg&#34; alt=&#34;&#34; class=&#34;product-mark&#34;&gt;&#xA;&lt;p&gt;&lt;strong&gt;Ozone&lt;/strong&gt; is Security Architects&amp;rsquo; heritage product: a Host Intrusion&#xA;Prevention System (HIPS) for Windows 2000, XP, and Server 2003 that protected&#xA;server and client machines from both known and unknown attacks — including&#xA;the worm epidemics of its day (Blaster, Sasser, MyDoom, Witty).&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-idea&#34;&gt;The idea&lt;/h2&gt;&#xA;&lt;p&gt;Unlike reactive products such as anti-virus and intrusion detection systems,&#xA;Ozone did not rely on constantly updated databases of &amp;ldquo;bad behaviour&amp;rdquo;&#xA;signatures. Instead it enforced &lt;strong&gt;good behaviour&lt;/strong&gt;: explicit policy describing&#xA;what each computer, application, and user is allowed to do — and nothing else.&#xA;A web server may listen on port 80 and serve pages; it may not execute&#xA;arbitrary programs or open connections to arbitrary hosts.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Introducing Cone of Silence: hardened agent pods</title>
				<link>https://securityarchitects.com/post/introducing-cone-of-silence/</link>
				<pubDate>Tue, 21 Jul 2026 09:00:00 -0700</pubDate>
				<guid>https://securityarchitects.com/post/introducing-cone-of-silence/</guid>
				<description>&lt;p&gt;Today we&amp;rsquo;re opening early access to &lt;strong&gt;&lt;a href=&#34;https://securityarchitects.com/products/cone-of-silence/&#34;&gt;Cone of Silence&lt;/a&gt;&lt;/strong&gt;&#xA;— agent pods secure enough for the original Chief and Agent.&lt;/p&gt;&#xA;&lt;p&gt;A pod is your own always-on AI agent: Claude, working for you around the&#xA;clock on a dedicated, hardened machine, reachable from your phone over&#xA;Telegram. Message it like a person; it reads, researches, codes, and runs&#xA;real tools — while everything it touches stays inside a security boundary&#xA;we built and operate.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Tens of thousands of exposed AI agents — sandboxing must be the default</title>
				<link>https://securityarchitects.com/post/sandbox-by-default/</link>
				<pubDate>Sat, 18 Jul 2026 10:00:00 -0700</pubDate>
				<guid>https://securityarchitects.com/post/sandbox-by-default/</guid>
				<description>&lt;p&gt;The always-on personal AI agent is the most exciting thing happening in&#xA;computing right now — and the most exposed. Between late January and early&#xA;February of this year, &lt;a href=&#34;https://www.bitsight.com/blog/openclaw-ai-security-risks-exposed-instances&#34;&gt;Bitsight&amp;rsquo;s internet-scale scanning&lt;/a&gt;&#xA;observed &lt;strong&gt;more than 31,000 distinct exposed instances&lt;/strong&gt; of the most popular&#xA;personal-agent stack, listening on its default port across technology,&#xA;healthcare, finance, government, and insurance networks. Independent&#xA;scanning teams reported even larger numbers, including thousands of&#xA;instances vulnerable to remote code execution.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Authinator3 is now open source</title>
				<link>https://securityarchitects.com/post/authinator3-open-source/</link>
				<pubDate>Tue, 14 Jul 2026 10:00:00 -0700</pubDate>
				<guid>https://securityarchitects.com/post/authinator3-open-source/</guid>
				<description>&lt;p&gt;We&amp;rsquo;ve published the core of &lt;strong&gt;Authinator3&lt;/strong&gt; as open source under the ISC&#xA;license: &lt;a href=&#34;https://gitlab.com/jowolf/authinator3&#34;&gt;gitlab.com/jowolf/authinator3&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Authinator is a web login gateway for firewalls. Authenticate over HTTPS,&#xA;click once, and your current IP address is granted passage through the&#xA;firewall — everyone else sees a wall. It replaces both permanently-open&#xA;management ports and brittle port-knocking schemes with something anyone can&#xA;operate from a phone: a login page.&lt;/p&gt;&#xA;&lt;p&gt;Authinator has guarded our own production gateways in one form or another&#xA;since 2007. Authinator3 is the modernized cross-platform release: a single&#xA;self-contained Go binary per platform, driving OpenBSD &lt;code&gt;pf&lt;/code&gt; tables (confined&#xA;by &lt;code&gt;pledge&lt;/code&gt;/&lt;code&gt;unveil&lt;/code&gt;, no sudo, no shell calls) or Linux &lt;code&gt;nftables&lt;/code&gt; sets&#xA;(under a locked-down systemd service). Default-deny, explicit allow, with an&#xA;audit view of every address currently cleared through.&lt;/p&gt;</description>
			</item>
			<item>
				<title>About</title>
				<link>https://securityarchitects.com/about/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://securityarchitects.com/about/</guid>
				<description>&lt;p&gt;Security Architects was founded in San Diego, California in 1999.&lt;/p&gt;&#xA;&lt;p&gt;The company offers advanced security solutions to organizations and&#xA;individuals needing to secure their networks and systems — security&#xA;&lt;a href=&#34;https://securityarchitects.com/products/&#34;&gt;products&lt;/a&gt; alongside professional &lt;a href=&#34;https://securityarchitects.com/services/&#34;&gt;services&lt;/a&gt; ranging&#xA;from penetration testing and code auditing to tailor-made security courses.&lt;/p&gt;&#xA;&lt;p&gt;Our original flagship product, &lt;strong&gt;Ozone&lt;/strong&gt;, was a Host Intrusion Prevention&#xA;System (HIPS) that protected server and client machines from both known and&#xA;unknown attacks. Rather than chasing an endless stream of &amp;ldquo;bad behaviour&amp;rdquo;&#xA;signatures, Ozone enforced &lt;em&gt;good&lt;/em&gt; behaviour — a least-privilege, policy-driven&#xA;approach that anticipated today&amp;rsquo;s zero-trust and application-allowlisting&#xA;technologies by two decades. In 2004 the Ozone agent was released free of&#xA;charge, kernel source code included.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Contact</title>
				<link>https://securityarchitects.com/contact/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://securityarchitects.com/contact/</guid>
				<description>&lt;p&gt;For additional information, email us:&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;&lt;a href=&#34;mailto:info@securityarchitects.com&#34;&gt;info@securityarchitects.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Please include your contact information, what you&amp;rsquo;d like us to consider doing&#xA;for you, your required timeframe, and the scope or budget for your needs.&lt;/p&gt;&#xA;&lt;p&gt;You will be contacted within one business day.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Privacy Policy</title>
				<link>https://securityarchitects.com/privacy/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://securityarchitects.com/privacy/</guid>
				<description>&lt;p&gt;&lt;em&gt;Effective date: July 10, 2026&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;Security Architects, Inc (&amp;ldquo;we&amp;rdquo;) operates securityarchitects.com. We keep data&#xA;collection to a minimum.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-we-collect&#34;&gt;What we collect&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Nothing directly.&lt;/strong&gt; This is a static website. We do not require accounts,&#xA;do not set cookies, and do not run analytics or advertising trackers.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Hosting logs.&lt;/strong&gt; The site is served by GitLab Pages, whose infrastructure&#xA;may record standard web server logs (IP address, user agent, pages&#xA;requested) for operational and security purposes. See&#xA;&lt;a href=&#34;https://about.gitlab.com/privacy/&#34;&gt;GitLab&amp;rsquo;s privacy policy&lt;/a&gt; for details.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Email.&lt;/strong&gt; If you contact us at &lt;a href=&#34;mailto:info@securityarchitects.com&#34;&gt;info@securityarchitects.com&lt;/a&gt;, we receive&#xA;what you send. We use it solely to respond to your inquiry and do not share&#xA;it with third parties.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;purchases&#34;&gt;Purchases&lt;/h2&gt;&#xA;&lt;p&gt;When product checkout is available, payment is handled entirely by a&#xA;third-party merchant-of-record payment processor. We never see or store your&#xA;card details. The processor&amp;rsquo;s own privacy policy governs the payment&#xA;transaction; this page will be updated to name the processor when checkout&#xA;launches.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Services</title>
				<link>https://securityarchitects.com/services/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://securityarchitects.com/services/</guid>
				<description>&lt;img src=&#34;https://securityarchitects.com/images/logo/services.svg&#34; alt=&#34;&#34; class=&#34;product-mark&#34;&gt;&#xA;&lt;p&gt;Security Architects has built security products and advised organizations&#xA;since 1999. We bring that builder&amp;rsquo;s perspective to consulting: we secure&#xA;systems the way people who ship them would.&lt;/p&gt;&#xA;&lt;h2 id=&#34;ai-security&#34;&gt;AI Security&lt;/h2&gt;&#xA;&lt;p&gt;Teams are shipping LLMs, RAG systems, and autonomous agents faster than the&#xA;security practices around them have matured. The attack surface is genuinely&#xA;new — prompt injection, tool abuse, training-data poisoning, agent&#xA;sandbox-escape — and most of it doesn&amp;rsquo;t yield to traditional controls. This&#xA;is our focus, and we come to it as practitioners: we build our own hardened&#xA;agent sandbox, &lt;a href=&#34;https://securityarchitects.com/products/claudette/&#34;&gt;Claudette&lt;/a&gt;, and run AI coding agents in&#xA;production under it every day.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Vintage</title>
				<link>https://securityarchitects.com/vintage/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://securityarchitects.com/vintage/</guid>
				<description>&lt;p&gt;This is the original Security Architects website — also known as&#xA;&lt;strong&gt;secarch.com&lt;/strong&gt; — as it ran in the 2000s, preserved byte-for-byte for&#xA;historical interest: table layouts, image-rollover menus, and all.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;&lt;a href=&#34;https://securityarchitects.com/vintage/secarch.com/index.html&#34;&gt;Enter the vintage site →&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Highlights of the era:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://securityarchitects.com/vintage/secarch.com/products.html&#34;&gt;Ozone&lt;/a&gt; — our Host Intrusion Prevention&#xA;System, with its &lt;a href=&#34;https://securityarchitects.com/vintage/secarch.com/ozone_technology.html&#34;&gt;technology overview&lt;/a&gt;&#xA;and &lt;a href=&#34;https://securityarchitects.com/vintage/secarch.com/faqs.html&#34;&gt;FAQ&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;The &lt;a href=&#34;https://securityarchitects.com/vintage/secarch.com/host_intrusion_prevention_system/ozone_host_intrusion_prevention_system_white_paper.pdf&#34;&gt;Ozone white paper&lt;/a&gt; (PDF)&lt;/li&gt;&#xA;&lt;li&gt;The &lt;a href=&#34;https://securityarchitects.com/vintage/secarch.com/OzoneAgentKernel.zip&#34;&gt;Ozone agent kernel source&lt;/a&gt;,&#xA;released free in 2004&lt;/li&gt;&#xA;&lt;li&gt;The &lt;a href=&#34;https://securityarchitects.com/vintage/secarch.com/services.html&#34;&gt;services&lt;/a&gt; we offered then — most of&#xA;which we &lt;a href=&#34;https://securityarchitects.com/services/&#34;&gt;still offer today&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;em&gt;Note: the original Windows agent installer is no longer distributed from this&#xA;site. The kernel source archive remains available above. The modern retelling&#xA;of the Ozone story lives on our &lt;a href=&#34;https://securityarchitects.com/products/ozone/&#34;&gt;products page&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
