Yafes | AppSec Engineer
Security in practice.

Latest

20
Jan
StokumNET Threat Model: A Practical STRIDE Analysis

StokumNET Threat Model: A Practical STRIDE Analysis

In an ideal world, threat modeling happens before the first line of code. You identify assets, map trust boundaries, enumerate
11 min read
18
Jan
StokumNET Security Roadmap: From Foundation to Enterprise-Grade

StokumNET Security Roadmap: From Foundation to Enterprise-Grade

Building a secure multi-tenant platform is never "done." The architecture I described in my previous post established the
7 min read
18
Jan
StokumNET/Architecture: Building a Secure Multi-Tenant Platform

StokumNET/Architecture: Building a Secure Multi-Tenant Platform

"Stokum" means "my inventory" in Turkish. "Net" means "clear" or "exact.
7 min read
16
Jan
Photo by Yafes.

Why I'm Building StokumNET (And Launching This Blog)

After seven years as a Staff Application Security Engineer at SugarCRM, I stepped away from corporate life to return to
3 min read