• Skip to main content
  • Skip to secondary menu
  • Skip to footer

Cybersecurity Market

Cybersecurity Technologies & Markets

  • Cybersecurity Events 2026-2027
  • Sponsored Post
  • Market Reports
  • About
    • GDPR
  • Contact

Trust Only Software That Can Explain Itself

October 2, 2026 By admin

I’ve put five project sites online lately. AltSql, VPN Works, Precomputing, Preconfiguration, BareProxy. Most of that happened in September; BareProxy squeezed in during the first couple of days of October, so parts of it still read like a design note. All five say Alpha or 0.1 right on the page, and I’ll get to why.

The plan was to write each one up separately, like a normal person. Then I lined the five up side by side and had an awkward moment. They’re the same project. Different problems, different users; one runs on a microcontroller, another sits in front of a web server. Under the hood, though, I keep building one thing over and over: a small tool you can ask “why?” and get a straight answer back.

So this is the post about that. It’s long. You’ve been warned.

AltSql, the one that fits in 15 KB

AltSql came first, and it changed how I work. My old habit was concept first: write the big document about the vision, then go build. With AltSql I flipped it. Prototype first, concept second. Build it, poke it until it breaks, then write down what it actually is. A document written after the prototype has a lot less room to lie.

The problem it goes after is a boring one, which is my favorite kind. A connected device keeps its readings in one format while the gateway wants rows in a SQL database, so somebody writes a converter. Then somebody has to babysit that converter for as long as the device stays in the field, and ten years isn’t unusual. That’s a long time to babysit anything.

AltSql takes the converter out. Its core engine compiles to about 15 KB of code for a microcontroller. The device keeps its readings and settings in its own flash, as plain key-value records, and goes on making decisions from its own data when the radio link drops. The gateway stores the very same records, byte for byte, and answers SQL over them. Same bytes at both ends. Nothing in the middle to rot.

The example I keep using is dumb on purpose: switch the fan on if the last ten readings were all above 60°C. That rule runs on the device itself, no round trip to anything. The dashboard asks about the same ten readings with one SELECT on the gateway. The How It Works page puts both halves next to each other (a few lines of C, one query), and I still like how short they are.

Then I got greedy. One engine turned into a plan for eight: the original plus seven new ideas, each with its own prototype and demo. Six of the new ones exist now, all on the engines page. AltSql Ask sends one SQL question to a whole fleet and brings back only the answers; AltSql Mesh lets devices share a table with no gateway at all. The seventh new one, a private-aggregation engine, is parked. It’s the hardest of the lot, and I’m not putting the word “private” on anything until someone from outside has tried to break it.

Status, plainly: everything so far has run on a PC with the flash chips and radio links simulated. Real chips come with the Beta. The live demos run the actual engine in your browser, compiled to WebAssembly, and you can cut a device’s power in the middle of a write to see what survives. Go ahead and cut it a few times. That’s what it’s there for.

VPN Works, the one that keeps coding agents on a leash

Here’s the bit about coding agents that never makes the landing page. They spend their whole day reading text written by strangers, in issues and on web pages. One planted instruction can be enough to make an agent send a deploy token somewhere it shouldn’t. On a machine-wide VPN that request leaves the same way as everything else, and afterwards nobody can tell you which program sent it.

VPN Works shrinks the network down to one program. The vpnw command seals the agent in a Linux network namespace whose only way out is vpnw itself. A script that ignores proxy settings finds no route anywhere. (I like that sentence a lot.) Every connection gets checked against a short policy and written to a record, then it leaves by the path you picked, direct or through an office proxy.

Day to day it’s four commands: run, trace, guard and learn. The last one is the reason I’d show this project to anybody. Nobody wants to write an allow list from scratch; I certainly don’t. So learn drafts one from a traced run. The agent does its normal work, vpnw writes down everything it reached for, and a human reads the draft and crosses out whatever looks wrong. Editing beats writing. That goes for allow lists, and it goes for blog posts.

One detail I’m a bit smug about: under a default-deny policy, a name that isn’t on the list never even gets looked up. So DNS can’t sneak data out either.

Then it grew a second engine. Scope takes the same watch-first, draft-later trick to the company VPN. It learns from traffic who actually uses which systems and drafts least-privilege rules for the gateway, so one stolen login stops opening the whole office network. Both engines are Alphas, tested on Linux. The live demo replays real runs of an agent trying to leak a token, and you can edit the policy against the real engine, compiled to WebAssembly. Loosen the policy and watch the token walk out the door. Tighten it and watch it bounce.

Precomputing, the one I built problem-first

Precomputing is where I set myself a new rule: start from a problem that costs somebody real money, then work backwards to the tech. Before that rule there was an idea for a cache invalidation engine for publishers. I killed it. Hard problem, tiny payoff.

There’s an old joke that computer science has two hard problems: cache invalidation, naming things and off-by-one errors. In September I lost an idea to each of the first two. The cache one I killed myself. The naming one was killed for me: a log reducer I really liked turned out to sit a little too close to somebody else’s registered trademark in the same field, and that was that. Some projects die in code review. That one died in a trademark register.

The good parts didn’t die, though. Two pieces of it moved into Precomputing: an MCP connection, so an AI agent can ask for a precomputed answer instead of chewing through raw rows, and agent traces where each prompt gets stored only once.

The core idea is almost embarrassingly simple. Most dashboards ask the same few questions all day (requests per endpoint, this month’s usage for one customer), and the usual setup recounts raw rows on every refresh. Precomputing does the counting once, as the data comes in. You write a short policy that names the answers you want and says how long each level of detail should live. It compiles to plain SQLite triggers. Every INSERT keeps the answers current, so reading one is just a lookup. Old detail fades on your schedule; unusual events are kept whole.

What I like most is that it’s still only SQLite. Open the file with any SQLite tool you already have and the answers are sitting there as plain views, with nothing running beside them. When triggers get too slow, a Go engine runs the same policy and writes the same file, value for value. The same policy language also drives a usage meter for billing, where a retried request counts once and a closed month stays closed. I find that last bit weirdly soothing.

It’s version 0.1, checked hard on simulated data and not yet run on anybody’s production traffic. The Policy Language walks through a policy line by line, and the SQL demo pushes three hours of simulated API traffic through a compiled policy in SQLite’s WebAssembly build, right there in your tab.

Preconfiguration, the boring files nobody wants to own

With Preconfiguration I started making myself answer four questions before writing a line of anything. Where’s the money? What real problem does it solve? Can I explain the tech in plain words? And why couldn’t somebody else knock it off over a weekend? It’s the screen you’d run on a startup pitch. Running it on yourself is less fun and a lot more useful.

Preconfiguration was the first project to go through that screen. The problem goes like this. Cloud coding agents start every task on a fresh machine. Before an agent can run a single test, something has to install the right runtime and start the database, and every platform wants those instructions in its own file. Copilot runs a setup workflow; Cursor builds a Dockerfile. Use two or three agents and you write the same setup two or three times, and a mistake usually turns up much later as an agent session that goes nowhere.

So I made the setup files build output. You describe the machine once, in a short preconfig.yaml, and preconfig build writes the file each platform reads. preconfig check reads existing files against each platform’s rules, which catches the quiet mistakes, like a Copilot job with the wrong name. Then preconfig verify does the part no reviewer can do by squinting: it runs the setup on an empty Ubuntu container, then runs the project’s tests. A setup file can look fine and still fail. A machine that started empty and passes the tests is proof, and I’ll take proof over a pretty YAML file any day.

When a setup breaks anyway, Preconfig Doctor reads the log (these can run past a thousand lines; nobody reads those for fun) and names the cause. If the fix belongs in the spec, it writes it there. The part I’m oddly proud of: Doctor has no model behind it. It works from rules, so the same log gets the same answer every time. In 2026 that’s almost old-fashioned. I mean it as a compliment.

Both are Alphas, measured on one Linux machine, and runs on the agent platforms themselves come with the Beta. The live demo mixes recorded runs with the real code running in your browser.

BareProxy, the baby

BareProxy is a couple of days old as I write this, so treat this section like a baby photo. It started as a short design note, on purpose, before any spec or prototype. The first cut of the code was meant to be a one-hour job. The site is a quick mockup on the same template as the others, and it’ll get rebuilt later. Probably.

The itch is nginx. Or rather the thin slice of nginx most sites actually use: TLS, a folder of static files, a couple of routes to an app, health checks, the odd reload. The config grows anyway, one regex at a time, until nobody’s quite sure which block handles a given URL.

BareProxy keeps its core to that slice and turns down regular expressions and scripting outright. Every matcher is an exact value, a prefix or a set. That one restriction buys the thing I wanted most: the requests a site can get fall into a finite number of classes, so the server can check every one of them. Which means it can answer questions.

bareproxy explain takes a URL and tells you which rule matched and which file or backend would serve it. It also tells you why the rules above it didn’t match, which is the part I always wanted from nginx. bareproxy why tells the story of a request that already happened, starting from the ID it carried in a response header. And bareproxy plan, the one I’d actually pay for, compares a new config with the running one before it goes live and lists the requests that would change hands. Write a rule that can never match because an earlier rule eats all its traffic, and you get a warning instead of a mystery.

The core serves a static folder directly too, with certificates from Let’s Encrypt, so a Hugo build needs no second server in front of it. That decision is brand new as well. Caching, rate limits and the rest are modules, compiled in only when you want them. The numbers on the site are design budgets: under 5,000 lines of Go in the core, and no dependencies from outside the Go project. Real speed and memory numbers against nginx come next. Until then the demo page shows each command’s output on a sample config.

So, I have a type

Put the five next to each other and the pattern isn’t subtle.

They’re all small, on purpose. AltSql is 15 KB on a chip. BareProxy has a line budget. Precomputing is a SQLite file with some triggers in it. I keep copying the way SQLite got built (start from practically one file, keep the footprint tiny), and when that didn’t stretch far enough I widened it to the nginx way. Funny thing: I’ve written two static site generators of my own, and every one of these project sites still runs on Hugo. Make of that what you will.

They all show their work. BareProxy explains its routing. VPN Works keeps a record of every connection. Doctor names the cause and gives the same answer twice. Precomputing’s answers are plain views anybody can open. AltSql keeps the same bytes at both ends of the link, so nothing hides in a translation step. I didn’t plan any of that. I only saw it when I lined them up for this post.

They all draft and let a person decide. learn drafts an allow list, Scope drafts gateway rules, Doctor drafts a fix into the spec and plan drafts the list of what’s about to change. A human reads it, crosses things out, then commits. I trust that loop far more than any tool that just goes ahead and does stuff.

They all have a demo you can poke. That started as a practical worry with AltSql: I didn’t want anyone to install anything, or to need my source code, only to see it work. WebAssembly sorted out both, and now every project gets a demo page whether it asked for one or not.

And they’re all honest about being early. Every page says Alpha or 0.1, and every page says what was simulated. AltSql hasn’t touched a real chip yet. VPN Works has only been tested on Linux. Precomputing hasn’t seen production traffic. Preconfiguration has been measured on one machine. I’d rather you read “simulated” from me than find it out the hard way.

One last confession. I gave my own checklist a name. Every project gets the same package (a site with a demo for each engine, plus the documents in Word and PDF), and I call it the Project Package Standard, capital letters and all. It sounds like something a committee wrote. It’s one person with a strong dislike of doing the same setup twice. Which, now that I type it out, is exactly what Preconfiguration is about.

If one of them gets something wrong, ask it why. It’ll tell you.

Filed Under: News

Footer

Recent Posts

  • Cybersecurity Weekly: Zero-Days Hit the Internet’s Defensive Edge as AI Starts Changing the Attack Cycle
  • Trust Only Software That Can Explain Itself
  • Zenity AI Agent Security Summit New York 2026, October 21, Pier Sixty, New York
  • Zenity AI Agent Security Summit London 2026, October 8, 8 Bishopsgate, London
  • SecTor 2026, October 6–8, Metro Toronto Convention Centre, Toronto
  • Cyera Takes $400 Million From Goldman Sachs, Pushing Its 2026 Funding to $1.4 Billion
  • Visa Buys BioCatch, Munich Re Buys At-Bay: The Biggest Cybersecurity Buyers Aren’t Security Companies
  • Flock Safety Cameras Run Android 8.1 With Hardcoded API Keys, Researchers Find
  • Brevo Supply Chain Attack Pushed ClickFix Malware to 100,000 Sites Through One Hardcoded Cloudflare Key
  • FBI and Coast Guard Boarded Hacked Oil Tankers, and Maritime OT Security Became a Budget Line

Media Partners

  • Defense Market
  • Technologies.org
  • Technology Conferences
Smart Shooter Wins Up to $150 Million U.S. Counter-Drone Contract for SMASH Systems
Aerial Refueling Became the Main Instrument of US Iran Policy, and Israel the Safest Place to Base It
Ondas (ONDS) Q2 2026: The Full-Year Guide Requires a $256 Million Fourth Quarter
Trump’s Steam Catapult Order Targets a Real Ford-Class Failure With the Wrong Fix
Cloudflare for Government Achieves FedRAMP Class D (High), Commits to DoD IL4 Pursuit
IonQ (IONQ) DARPA Clock Award: $28 Million Contracted, $300,000 Per Clock in the Option
Aurelius Systems Raises $40M to Scale Autonomous Counter-Drone Defense
Antares Raises $470 Million to Field Nuclear Microreactors on U.S. Military Bases by 2028
L3Harris Signs Seven-Year Frameworks to Quadruple THAAD Propulsion and Nearly Triple PAC-3 MSE Motor Output
Anduril’s $100 Billion Talks Assume a Capability Gap the UK and US Just Tried to Measure
AI Infrastructure Moves Beyond GPUs as Billions Flow Into Interconnects, Cloud, Robotics and Agent Systems
Supermicro Is Now Shipping NVIDIA Vera Rubin NVL72 Racks, With 1,152-GPU Scalable Units Ready to Order
Synopsys and TSMC Certify A14 Design Flows and Roll Out Agentic AI Chip Design Tools
Bird.com Secures $450M in Debt Financing and Opens Its Messaging Network to AI Agents
Meta AI Glasses Become the First Consumer Device to Record Dolby Atmos Audio
Insurify Blocks Meta’s Muse AI Agent, Saying Scraped Insurance Quotes Mislead Consumers
Basecamp Research Raises $140M Series C, With NVIDIA and Anthropic Backing AI-Designed Gene Therapies
USD.AI Closes Its Largest GPU Loan Yet, $128.9M Backed by 32 NVIDIA GB200 NVL72 Racks
NG.CASH Raises $15M From Blockchain Capital to Expand Credit for Young Brazilians
Realset AI and Flatkey Raise $10M Series A for Real-World AI Training Data and a One-Key Model Gateway
JNUC 2026, September 23–25, Kansas City Convention Center, Kansas City
Startup World Cup Grand Finale 2026, November 4–6, Hilton San Francisco Union Square, San Francisco
FYUZ 2026, November 3–5, The Westin Seattle, Seattle
ONUG AI Networking Summit 2026, October 28–29, Penn District, New York
Networking Field Day 2026, October 6–9, San Jose
Nova Future Summit 2026, September 28–30, Napa
Breakbulk Americas 2026, September 22–23, George R. Brown Convention Center, Houston
Gartner CIO & IT Executive Conference 2026, September 21–23, Sheraton São Paulo WTC Hotel, São Paulo
ITC Vegas 2026, September 29–October 1, Mandalay Bay, Las Vegas
Sidoti Small-Cap Virtual Conference: September 23-24, Online

Media Partners

  • Market Analysis
  • Market Research Media
  • Analysis.org
An AI Lab Is Paying Up Front for Atlas Energy’s (AESI) Generators as Agentic AI Multiplies Token Demand
Oracle’s Force Majeure Notice on Project Jupiter Shows Where AI Data Center Risk Is Landing
AI Infrastructure Credit Costs Rise as CoreWeave-Tied Bonds Price at 9.25% and China Chipmaker Profits Jump 620%
OpenAI and Anthropic Cut AI Model Prices as $1.75B in Funding Flows to Data, Security and Infrastructure
Semiconductor Revenue Hits Record $425B in Q2 2026, but Omdia’s $500B Q3 Forecast Implies Growth Halves
AI Extinction Warnings Went Global in Six Days. Nothing in the Technology Changed.
Anthropic Walks Away From $6 Billion Decart Acquisition: The Deal Was About Inference Cost, Not World Models
VR Status Report 2026: Quest Sales Keep Falling While Smart Glasses Take the Money
The Case That the US Can Grow Out of $40 Trillion in Debt: Three Conditions the Clinton Surpluses Actually Met
The $40 Trillion Debt: Why AI Capex Raises Treasury Borrowing Costs Faster Than It Raises the Tax Base
The Economist Is Right About a Million AI Jobs. It’s a Construction Boom, Not a Tech Boom.
AI Slop Earns Higher CPMs Than Clean Inventory: Why the Ad Market Cannot Fix the Web It Funds
Weekly Network Analytics, July 19 to July 25, 2026: Visits Up 14%
Adobe (ADBE) and Figma (FIG) Have Each Lost Roughly Half Their Value to a Competitor Set Worth $34 Million
Getty Images Kills the $3.7 Billion Shutterstock Merger Rather Than Sell the Editorial Business the UK Demanded
Fox’s $22B Roku Deal: 4.6x Sales, Paid in 1.5x Stock
Tuesday Open: AI Earnings Engine Holds the Line as Iran Overhang Fades to Noise
China’s U.S. Treasury Holdings: The Great Repositioning (2021–2025)
Infographic: Why the 2025 CIPA Data Proves the APS-C Renaissance is Real
How WiFi Changed Media
Akamai’s 17% Jump on Anthropic’s $11.6B Deal Skips the 5% Warrant Anthropic Gets in Return
Adobe Closes $340 Million Topaz Labs Deal With ADBE Trading at 10x Earnings
Omdia’s Record $425 Billion Chip Quarter: Memory Took Roughly 80% of the New Revenue
SanDisk (SNDK): The 2027 NAND Supply Wave Arrives in 2029
Schwab’s August STAX Falls to 57.50 as Retail Sells Software and Buys Chips Off the July Low
Broadcom Q3 FY26: The Q4 Guide Implies a 55% Incremental Operating Margin Against 67.9% Delivered
Tempus AI (TEM) Clears FDA for ECG-PH: A Third Cardiology Device Its Own CFO Says Generates No Revenue
Nasdaq Falls 1.2% as Oil Tops $85 and the 30-Year Hits 5.32%: Only One Input Is Actually New
Marvell (MRVL) Catalyst Calendar Into Year-End: The $126-to-$400 Target Spread Resolves on October 6, Not August 27
Lattice Semiconductor Q2 2026: A 69.5% Gross Margin Guide Undercuts the AMI Accretion Story

Copyright © 2026 CybersecurityMarket.com

Media Partners: Technologies · Market Analysis · Market Research · Photography · API Coding · App Coding · Blockchaining · Referently