Tom Stacy, CISSP®
I've spent years in authentication and identity security — running red team engagements that touch identity providers, and learning the same lesson every time: the client is confident until you show them proof. This site is where that proof gets built, documented, and shared.
The arc
The research started in the Identity pillar: OAuth attack chains, reproducible labs, and what the attacks look like from the defender's side. The archive is complete and stays — those posts are the foundation of everything else.
The expansion is across the full Zero Trust model. Devices, Networks, Applications, and Data — with one thread running through all of it: PII redaction. The same discipline that catches a stolen authorization code also stops a customer's name from leaking into an LLM prompt.
The tools
- FlawedToken — the open-source vulnerable OAuth lab. Free, documented, toggleable.
- ShroudCloud — the detection engine for PII and secrets across every pillar. Documents, logs, and AI pipelines.
How I work
Everything here is practitioner-tested: reproduced against a purpose-built lab, with the conditions, the logs, and the fix written down. No theory without proof. That's the standard this site holds, and it's the standard ShroudCloud is built to.