Knowledge

What we end up repeating in every conversation anyway

We write only about what we know from our own work. We make no claims about other people's products without evidence with a source and a date.

Check before you click or pay

6 articles

People and companies who want to check a site before entering data or paying · 8 minutes

How to check if a website is safe: 7 checks before you trust it

A padlock and https do not mean a site is honest. Check the domain, its age, the CERT Polska warning list and company details. Steps for phones and banks too.

People and companies who got a suspicious message and want to check it before clicking or paying · 8 minutes

How to check if an email is real: sender, headers and DMARC

Check the real sender address, the domain and its age, and the SPF, DKIM and DMARC results in the original message in Gmail and Outlook. Plus: Facebook emails.

Accounting, purchasing teams and business owners who pay invoices by bank transfer · 9 minutes

Fake invoices and bank account change emails: how to check

An email about a new bank account number is classic BEC fraud. A phone check routine, the Polish VAT white list, what KSeF does and what to do after paying.

Anyone who got a link by email, text or chat app and is not sure where it leads · 8 minutes

How to check if a link is safe before you click it

How to read a link's address without clicking, expand a short link, check the domain on the CERT Polska list and spot 'payment link' scams on marketplaces.

Online shoppers and companies ordering from a new supplier online · 8 minutes

How to check if an online shop is legit: 8 checks before you buy

Check the shop's company in Polish registers, its terms and returns, domain age, reviews, the CERT Polska warning list and consumer warnings. Then pay by card.

People and companies installing a phone app or choosing a web app (SaaS) for work · 8 minutes

How to check if an app is safe: mobile apps and business SaaS

Mobile apps: source, publisher, permissions, Data safety label. Web apps for business: privacy policy, subprocessors, data location, DPA, who gets your data.

AI at work

3 articles

Is this AI tool safe

4 articles

New threats: agents, MCP, prompt injection

5 articles

Companies that deploy chatbots, AI assistants or agents, or use them to read outside documents · 8 minutes

What is prompt injection and how do you protect against it?

Prompt injection hijacks an AI model with instructions hidden in content it reads. Direct vs indirect attacks, the resume example and what actually helps.

Companies and teams connecting MCP servers to Claude, ChatGPT, Cursor, Copilot or their own agents · 8 minutes

What is an MCP server, how does it work and is it safe?

An MCP server gives an AI assistant tools and data. How it works, local vs remote, tool poisoning and rug pulls, and how to check a server before connecting.

Companies deploying AI agents or letting staff use browsers and assistants that act on their behalf · 8 minutes

What is an AI agent and how do you use one safely at work?

An AI agent takes actions, not just answers. How it differs from an assistant, OWASP risks, agentic browsers, permissions, human approval and logs.

Builders using Lovable, Bolt, Cursor and similar tools, agencies, and companies that commission such apps · 9 minutes

What is vibe coding and how do you secure a vibe-coded app?

Vibe coding is building apps with AI without reading the code. Common mistakes: keys in the browser, no RLS, public files. What Lovable does, plus a checklist.

Individuals, finance teams, executives and anyone who approves payments or takes calls from "the boss" · 8 minutes

How to spot a deepfake: fake video, cloned voice and scam ads

How to spot a deepfake by image and voice, how AI voice scams posing as family or the CEO work, and what the law and Article 50 of the AI Act say.

Data leaks

1 article

Regulation: AI Act and NIS2

2 articles

How we work

3 articles