<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security on Bootstrapping.org</title>
    <link>https://bootstrapping.org/tags/security/</link>
    <description>Recent content in Security on Bootstrapping.org</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 02 Oct 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://bootstrapping.org/tags/security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>VPN Works: Security Without Hiring a Security Team</title>
      <link>https://bootstrapping.org/vpn-works-security-without-hiring-a-security-team/</link>
      <pubDate>Fri, 02 Oct 2026 00:00:00 +0000</pubDate>
      <guid>https://bootstrapping.org/vpn-works-security-without-hiring-a-security-team/</guid>
      <description>&lt;p&gt;Bootstrapped founders know that hiring a security specialist is out of reach. You need your infrastructure to be safe, but you also need to keep payroll lean. The tradeoff has always been uncomfortable: either you build products and hope nothing breaks, or you slow down to implement security controls that you&amp;rsquo;re not sure you even need.&lt;/p&gt;&#xA;&lt;p&gt;Now add coding agents to the mix. An agent can cut your feature development time in half, but you have no idea what it&amp;rsquo;s connecting to. It reads code from your repo, issues from your tracker, snippets from web pages. One bad instruction planted in text and the agent could send your deploy credentials to a server you don&amp;rsquo;t control. You want to use the agent, but the security risk feels real.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
