Notes on securing software against software.

Definitions, method, and what the public record teaches. Written for CTOs, CISOs and the boards that ask them questions.

Definition

What "Mythos Safe" means, and how to know if you are

Mythos Safe is a testable state: every security assumption in a product written as a rule and re-tested on every release against what frontier models can do.

MATT Research · 6 min read
The record

The Hugging Face breach: five lessons for CXOs

OpenAI's models escaped a test sandbox and ran code on Hugging Face servers for four days with no human steering. Five lessons for leadership, from the record.

MATT Research · 7 min read
Method

Why annual pentests fail against AI attackers

The annual pentest assumed a vulnerability took an expert weeks to find. In 2026 it takes a prompt. Where the model breaks and what replaces it.

MATT Research · 6 min read
AI-written code

AI-written code: the checks reviewers skip

Generated code is syntactically clean, passes review and omits the ownership check the author assumed. The failure modes of AI-written code, with tests.

MATT Research · 7 min read
Compliance

SOC 2 in the age of agentic attacks

SOC 2 proves controls existed on audit day; agentic attackers test them every day. How to turn compliance evidence into live test results auditors accept.

MATT Research · 6 min read