Architecture posts

  • Architecture
  • Development
  • Tooling

Fire the slop cannons (safely): on coding agents and sandboxing

  • icon Sep 22, 2026
  • by Ben "Fuzzy" Shonaldmann
  • icon 11 minutes read
  • icon 2141
Last time, we covered AI risks inside and against your organization, and how to reduce them. In this post, we’ll touch on some specific risks and mitigations for using coding agents. Coding agents are a specific case of “AI in your organization,” so …
Read more
  • Architecture
  • Detection & response

Slopportunity knocks: how AI impacts security practices for startups

  • icon Sep 22, 2026
  • by Ben "Fuzzy" Shonaldmann
  • icon 14 minutes read
  • icon 2891
Latacora has spent lots of time talking with startups about AI and how security practices need to evolve to keep up. It comes up in conversations with current and prospective clients, with people we meet at conferences, and occasionally, with random …
Read more
  • Architecture
  • Tooling
  • Detection & response

Stytch & Latacora: A Security Partnership Retrospective

  • icon May 22, 2026
  • icon 3 minutes read
  • icon 606
From growing startup to Twilio integration # Stytch and Latacora worked side by side to ensure that the developers and end users relying on Stytch’s platform benefited from a security program built for the sensitivity and criticality of the …
Read more
  • Architecture
  • Cloud security

OIDC workload identity on AWS

  • icon Nov 04, 2025
  • icon 11 minutes read
  • icon 2335
Update: after years of being on the wish list of a ton of top AWS teams, AWS released a built-in version of this feature about two weeks after we published this. Never let it be said gentle ribbing doesn’t work. Also, thanks AWS! We meant it …
Read more