Engineering Field Notes

Technical Journal & Security Guides

Practical analysis of software vulnerabilities, architectural defense patterns, and manual code review practices from our consulting engagements in Taiwan.

Deconstructing Broken Object Level Authorization (BOLA) in Multi-Tenant APIs
API Security June 17, 2026 7 min read

Deconstructing Broken Object Level Authorization (BOLA) in Multi-Tenant APIs

Why relying on gateway-level authentication tokens leaves resource-level access controls vulnerable, and how to structure tenant-scoped repository layers in modern backends.

By Meixuan Li Read Full Guide →
Why Automated SAST Scanners Miss Context-Dependent Business Logic Vulnerabilities
Code Review Methodology May 11, 2026 9 min read

Why Automated SAST Scanners Miss Context-Dependent Business Logic Vulnerabilities

Static application security testing tools are essential for syntax-level sanitization, but human-led code review remains indispensable for tracing complex business rules and state machines.

By Chenghao Lin Read Full Guide →
Establishing Practical Threat Modeling Rhythms for Fast-Moving Engineering Teams
Threat Modeling April 3, 2026 6 min read

Establishing Practical Threat Modeling Rhythms for Fast-Moving Engineering Teams

How to implement structured STRIDE threat modeling in sprint cycles without slowing down product delivery or creating cumbersome documentation overhead.

By Meixuan Li Read Full Guide →
Securing Cryptographic Key Lifecycle and Secrets in Distributed Microservices
Cryptography & Architecture March 20, 2026 8 min read

Securing Cryptographic Key Lifecycle and Secrets in Distributed Microservices

Common cryptographic implementation anti-patterns uncovered during source reviews, and how to design automated key rotation and envelope encryption.

By Chenghao Lin Read Full Guide →
Stay Informed

Have a Question Regarding Code-Level Security?

Our principal auditors frequently answer architectural questions and review critical open-source patterns for engineering teams.

Contact Our Editorial & Audit Team