Security & Privacy

Password managers, encryption, auditing and staying private.

Nothing launched in this category yet.

Be the first

About Security & Privacy

Security tooling carries an unusual burden: the failure mode is silent. A tool that does not work still feels exactly like a tool that does, right up until the moment it matters. That makes claims harder to verify and trust more important than in any other category.

What is collected here spans password managers and authentication, encryption and secure storage, VPNs and network privacy, vulnerability scanning and dependency auditing, secrets management, and the privacy tools that reduce how much of your activity is collected in the first place.

The most reliable quality signal is openness about how something works. Published source, documented threat models, and independent audits with the findings visible — including the ones that were unflattering. A security product that cannot tell you what it protects against and what it does not is asking for faith rather than trust, and this is the category where that distinction matters most.

Be particularly careful with anything that positions itself as protecting privacy while operating a business model that depends on data. Free VPNs are the classic example: routing all your traffic through a provider is a substantial act of trust, and if you are not paying, it is worth understanding precisely how the service is funded.

For developers, the interesting movement is towards tools that fail loudly and early — dependency scanners in CI, secrets detection before commit, and infrastructure checks that block a deploy rather than filing a ticket. The shift from reporting problems to preventing them is where most of the practical value now sits.

Password managers remain the highest-leverage single change most people and most teams can make, and the differences between the good ones are smaller than the difference between using one and not. If you are choosing for a team, weight recovery and offboarding heavily: what happens when someone leaves, and what happens when someone loses their device, are the scenarios you will actually encounter.

For makers launching here, expect to be asked hard questions and treat that as a good sign. Publish your threat model. Say what you have not audited. Explain your key handling in enough detail that someone qualified could find a flaw. Vagueness in this category reads as evasion, and the people you most want as early users are exactly the ones who will notice.

From the blog

Reading on launching, ranking and security & privacy.

All posts