About

Tom Stacy, CISSP®

I've spent years in authentication and identity security — running red team engagements that touch identity providers, and learning the same lesson every time: the client is confident until you show them proof. This site is where that proof gets built, documented, and shared.

The arc

The research started in the Identity pillar: OAuth attack chains, reproducible labs, and what the attacks look like from the defender's side. The archive is complete and stays — those posts are the foundation of everything else.

The expansion is across the full Zero Trust model. Devices, Networks, Applications, and Data — with one thread running through all of it: PII redaction. The same discipline that catches a stolen authorization code also stops a customer's name from leaking into an LLM prompt.

The tools

  • FlawedToken — the open-source vulnerable OAuth lab. Free, documented, toggleable.
  • ShroudCloud — the detection engine for PII and secrets across every pillar. Documents, logs, and AI pipelines.

How I work

Everything here is practitioner-tested: reproduced against a purpose-built lab, with the conditions, the logs, and the fix written down. No theory without proof. That's the standard this site holds, and it's the standard ShroudCloud is built to.