Blog
Notes from the team.
Architecture decisions, privacy engineering, and the occasional argument about the shape of AI-era engineering work. We write down what we built and what it cost.
We Scanned 27,075 Real Developer Prompts to ChatGPT and Found Three Live API Keys
We ran HeimWall's detection engine over DevGPT, a public research corpus of real developer↔ChatGPT conversations. Here is what actually leaks, what fires falsely, and why a 1.12% alert rate is the number that matters.
Why Your Team Needs an AI Safety Score (And How to Build One)
A VP Engineering without a safety score is the 2018 SRE without an SLO. Here is the math we landed on, the four traps to avoid, and why this number is a leading indicator, not a verdict.
The Invisible AI Data Leak: What Your Engineers Ship to Cursor Every Day
Three years after Samsung, the leak surface moved from a browser tab to a desktop IDE. Here's why the channel is invisible to classical tooling, and what a usable signal would look like.
Why we built HeimWall
The fastest enterprise tool adoption in history shipped without a control plane. Managers are flying blind. Here's what we're building about it.
Observability is not surveillance
How we architected HeimWall so the manager sees signal, not content, and why that choice is structural, not cosmetic.