Notes from the bench
Short pieces on how we work: what we actually do in a load test, a threat model or a bug report, and why. Method, not marketing.
How we load test a checkout
The number you want is not how many users the system can take. It is what breaks first, at how many, and what to change.
A threat model for a payments API, in an afternoon
A threat model is not a document. It is a list of the things that would hurt most, written before anyone tests anything.
Bug reports a developer can act on without a call
A good bug report is a reproduction, a gap and a consequence. Everything else is decoration.