Knowledge
What we end up repeating in every conversation anyway
We write only about what we know from our own work. We make no claims about other people's products without evidence with a source and a date.
Check before you click or pay
6 articles
People and companies who want to check a site before entering data or paying · 8 minutes
How to check if a website is safe: 7 checks before you trust it
A padlock and https do not mean a site is honest. Check the domain, its age, the CERT Polska warning list and company details. Steps for phones and banks too.
People and companies who got a suspicious message and want to check it before clicking or paying · 8 minutes
How to check if an email is real: sender, headers and DMARC
Check the real sender address, the domain and its age, and the SPF, DKIM and DMARC results in the original message in Gmail and Outlook. Plus: Facebook emails.
Accounting, purchasing teams and business owners who pay invoices by bank transfer · 9 minutes
Fake invoices and bank account change emails: how to check
An email about a new bank account number is classic BEC fraud. A phone check routine, the Polish VAT white list, what KSeF does and what to do after paying.
Anyone who got a link by email, text or chat app and is not sure where it leads · 8 minutes
How to check if a link is safe before you click it
How to read a link's address without clicking, expand a short link, check the domain on the CERT Polska list and spot 'payment link' scams on marketplaces.
Online shoppers and companies ordering from a new supplier online · 8 minutes
How to check if an online shop is legit: 8 checks before you buy
Check the shop's company in Polish registers, its terms and returns, domain age, reviews, the CERT Polska warning list and consumer warnings. Then pay by card.
People and companies installing a phone app or choosing a web app (SaaS) for work · 8 minutes
How to check if an app is safe: mobile apps and business SaaS
Mobile apps: source, publisher, permissions, Data safety label. Web apps for business: privacy policy, subprocessors, data location, DPA, who gets your data.
AI at work
3 articles
Companies whose teams use ChatGPT, Copilot, Gemini or other AI tools · 8 minutes
AI use policy for companies: template and what it must cover
A short AI use policy template you can copy. What the GDPR and Article 4 of the EU AI Act actually require, which data staff may enter and how to roll it out.
Companies and employees who use ChatGPT for documents, email and customer data · 8 minutes
Can you paste company data into ChatGPT? GDPR and plans
What you can and cannot paste into ChatGPT at work. Free, Plus, Business and Enterprise compared, the training setting and what GDPR regulators say.
Business owners, IT teams and people responsible for data protection · 7 minutes
Shadow AI: what it is, how to spot it and how to reduce it
Shadow AI means AI tools used at work without the company knowing. Examples, research figures, how to detect it in your company and reduce it without bans.
Is this AI tool safe
4 articles
Companies that use ChatGPT or need rules for their team · 8 minutes
Is ChatGPT safe for business data? Facts and settings
What OpenAI does with what you type into ChatGPT: training, 30-day retention, Business and Enterprise plans, EU data, the Garante fine. As of October 2026.
Companies that use Copilot or are deciding which version to allow · 8 minutes
Does Copilot collect your data? Consumer, Microsoft 365, GitHub
What happens to data in Copilot: model training, retention, where it is processed and how to turn it off. Three products, three rule sets, October 2026.
Businesses and people who use Gemini or are considering it in Google Workspace · 8 minutes
Is Gemini safe? Privacy in the Gemini app and Google Workspace
What Google does with Gemini chats: human review, model training, retention and data regions. Personal accounts vs Google Workspace, with settings step by step.
Companies whose staff reach for DeepSeek, and people who want to use it privately · 8 minutes
Is DeepSeek safe? The app, the open model and your company data
Where DeepSeek stores your chats, whether it trains on them, what Italy, Poland and Berlin regulators did, and how the app differs from a model you run locally.
New threats: agents, MCP, prompt injection
5 articles
Companies that deploy chatbots, AI assistants or agents, or use them to read outside documents · 8 minutes
What is prompt injection and how do you protect against it?
Prompt injection hijacks an AI model with instructions hidden in content it reads. Direct vs indirect attacks, the resume example and what actually helps.
Companies and teams connecting MCP servers to Claude, ChatGPT, Cursor, Copilot or their own agents · 8 minutes
What is an MCP server, how does it work and is it safe?
An MCP server gives an AI assistant tools and data. How it works, local vs remote, tool poisoning and rug pulls, and how to check a server before connecting.
Companies deploying AI agents or letting staff use browsers and assistants that act on their behalf · 8 minutes
What is an AI agent and how do you use one safely at work?
An AI agent takes actions, not just answers. How it differs from an assistant, OWASP risks, agentic browsers, permissions, human approval and logs.
Builders using Lovable, Bolt, Cursor and similar tools, agencies, and companies that commission such apps · 9 minutes
What is vibe coding and how do you secure a vibe-coded app?
Vibe coding is building apps with AI without reading the code. Common mistakes: keys in the browser, no RLS, public files. What Lovable does, plus a checklist.
Individuals, finance teams, executives and anyone who approves payments or takes calls from "the boss" · 8 minutes
How to spot a deepfake: fake video, cloned voice and scam ads
How to spot a deepfake by image and voice, how AI voice scams posing as family or the CEO work, and what the law and Article 50 of the AI Act say.
Data leaks
1 article
Regulation: AI Act and NIS2
2 articles
Companies that build, buy or simply use AI tools · 9 minutes
EU AI Act: what it is, who it applies to and key dates
The EU AI Act in brief: who it applies to, every date after the 2026 amendments, Poland's AI systems act and how to label AI content under Article 50.
Medium and large companies in sectors covered by the Polish cybersecurity act, public bodies and their suppliers · 9 minutes
NIS2: who it applies to and how to comply in Poland in 2026
NIS2 in Poland is the amended National Cybersecurity System Act, in force since 3 April 2026. Who it covers, requirements, deadlines and fines.
How we work
3 articles
No-code teams, agencies, app builders · 6 minutes
Five things that show up in apps built fast
Not exotic vulnerabilities, but the same mistakes that recur in apps built in a week. What they look like, why they happen and how to check for them yourself.
People who decide on buying software · 5 minutes
How to read a vendor security assessment
How a number differs from a decision, why missing evidence doesn't mean “secure” and which four questions to ask about any report someone shows you.
Agencies, teams buying an audit, system owners · 5 minutes
What a security testing authorization must contain
Nine elements without which consent to testing protects neither the party commissioning it nor the tester. With an explanation of what each one is for.