Writing in progress.
Nothing is published here yet. When it is, it will be findings with method and evidence attached — not summaries of other people's advisories, and not posts written to fill a page.
Three kinds of thing
Technical reports
Original findings on data security technologies, with the method written out so the result can be reproduced or disputed.
Advisories
Coordinated disclosures on a 90-day clock, with the vendor's response quoted unedited and affected versions listed in full.
Practice notes
Shorter pieces from delivered work — what a diagnostic actually turns up, and which fixes hold.
The methodology behind all of it is already written. Inside the Adversary's Loop is a 444-page doctrine covering the construction pipeline, the three measurement lenses, and the operating posture — including worked examples against a real DLP service.
Broader themes we expect to write about: information asymmetry as a measurable property rather than a metaphor, where machine augmentation genuinely helps a defender and where it only appears to, and what it takes to make serious capability affordable to organisations that will never staff a large team.
Ninety days, then it is public
We report to the vendor first with a working reproduction, start a 90-day clock, and publish when it expires or when a fix ships — whichever comes first. Extensions are granted when a vendor is visibly working and asks in writing. Users of a product deserve to know it was broken.
Reporting something to us? Use security@polygoncyber.com. Tell us what you have before you send details, and we will arrange a channel for anything that should not travel in the clear.