Learn
In-depth, vendor-neutral explainers on the metrics, security, and compliance practices behind modern software — and how they are changing as AI reshapes how software is built and governed.
Software development metrics: the full catalog, organized by lens
A vendor-neutral catalog of software development metrics organized by lens: delivery, flow, reliability, quality, security, compliance, finance, and board risk.
AI development metrics: a catalog for AI-assisted SDLC and AI systems
A vendor-neutral catalog of AI development metrics: the AI-assisted SDLC and the AI systems you ship, each with what it measures and how it gets gamed.
DORA metrics without spreadsheets: deriving the four from systems you already run
How to derive the four DORA metrics from the systems you already run, and the definitional choices that decide whether the numbers mean anything.
KEV and EPSS: prioritizing vulnerabilities by exploitation, not severity
Why CVSS severity alone is a poor work queue, and how CISA KEV and FIRST EPSS change the order — with each signal's blind spot stated.
Per-contributor pricing, explained
What a per-active-contributor meter actually counts, the questions to ask any vendor using one, and where it goes wrong for buyer and vendor alike.
SBOM blast radius: answering 'where do we use it?' honestly
How to answer 'which repositories use this package below this version' — and why a manifest-derived answer and a lockfile-derived one are not the same claim.
AI governing AI: how law and measurement are co-evolving
AI increasingly builds and reviews AI. How the EU AI Act, ISO 42001, and NIST AI RMF shift governance from annual audits to continuous, verifiable assurance.
California GovOps and its role in state AI governance
California's GovOps agency oversees state IT, procurement, and workforce — and has become the hub coordinating California's AI policy and executive orders.
Public-sector AI governance: how California's GovOps runs the model
How California's GovOps agency governs public-sector AI — executive orders N-12-23 and N-5-26, GenAI procurement guidelines, training, and citizen services.
Public-sector GenAI procurement: how California buys AI safely
How California vets and buys generative AI: EO N-12-23, the 2024 GenAI Guidelines, the SIMM 5305-F risk assessment, and vendor attestations directed under EO N-5-26.
Separation of duties when AI writes — and reviews — the code
Separation of duties keeps the maker from being the checker, a core SOX and COSO control. See how AI-authored code strains it and the patterns that hold it.
Test data management in the AI era: realistic data without the risk
Test data management in the AI era: provisioning realistic, compliant test data, why production data in test is a finding, and where synthetic data fits.