// Blog
Notes on building for the long clock.
Essays on building AI-native SaaS inside a studio, unit economics, and what we're learning building our brands.
3 of 39 essays match your filters
Security posture on a long hold: three programs, not a compliance event.
Identity and access, data lifecycle, and incident response are three concurrent programs that produce compliance as a byproduct. The framework Cobalt Glacier uses to retune security posture after close — and why it ends up being a topline lever.
Open source dependency risk in B2B SaaS diligence.
License risk is the smallest of three. License drift, maintainer collapse, and supply-chain compromise are the underwriting questions that matter on a twenty-five-year hold. The Cobalt Glacier dependency workstream and remediation pattern.
Engineering productivity on a twenty-five-year clock.
Velocity is the wrong instrument. On a permanent-capital hold, engineering productivity is measured by change-failure rate, lead time to a paying customer, share of compounding work, and incident minutes per active customer.
// Subscribe
New essays, in your inbox.
One email when we publish. No drip campaigns, no upsells — just the work.