Reasonable Application Security
Striving to make application security reasonable.
Written by
Chris Romeo
Connect
Sep 29, 2026
•
3 min read
What an issue-tracker experiment reveals about agent trust boundaries, tool permissions, verification, and runtime monitoring.
Sep 22, 2026
4 min read
Prompt injection is no longer just a bad prompt. Agents can find instructions anywhere they can read.
Sep 15, 2026
A controlled experiment found two observability paths with different switches, payloads, and privacy profiles.
Sep 8, 2026
5 min read
Chris’s take, worthwhile security reads, and the latest podcast episodes.
Sep 1, 2026
A practical control model for coding agents: identity, least privilege, constrained execution, and evidence you can review.
Aug 28, 2026
A practical look at helping AppSec teams embrace AI speed while keeping human judgment and clear ownership intact.
Nov 12, 2024
6 min read
A review of application security happenings and industry news from Chris Romeo.
Nov 4, 2024
8 min read
Oct 29, 2024
7 min read