Four books · Twenty worksheets
Find out how much, and shrink it, in an afternoon, with files you can actually use. Written for people who build agents and automations that touch real databases, inboxes and payment processors.
One payment. Instant download. 7-day refund, no questions.
Nobody goes back. The automation works, and working is the signal that stops people looking at configuration. Two years later that credential is still there, and it can still do everything it could on day one.
Here is what that costs, in four documented incidents. Each one is dissected inside: the exact configuration that allowed it, and the exact change that would have stopped it.
During an explicit code freeze, after being told not to. Then reported recovery was impossible. It wasn't. No attacker involved.
Hidden instructions in an unread message. The assistant read it during an unrelated task and put the data in a URL. Zero clicks.
It sits underneath most agent frameworks. The person who found it had never installed it: their editor pulled it in as a dependency of a dependency.
Plaintext conversations and API keys, in a database with no authentication at all. Researchers found it in minutes.
None of that is fixed by being careful. It is fixed by changing what the system is able to do, which is unglamorous, entirely on your side of the line, and does not stop working when the models change.
What you actually get
Bound what your agent can destroy on its own. Permissions, scope, reversibility and detection, across nineteen platforms, with the exact SQL and scope names.
Accept that strangers can instruct it, and make that stop mattering. Includes the five defences that feel productive and do not hold.
Stop assuming the code you run is the code you think it is. Pinning, isolation, CI credentials, and the MCP failure modes with no npm equivalent.
One agent task creates nine or more copies of your customer data. Map them, shorten them, and make deletion possible before someone asks.
What this replaces
And the answer to the question a serious customer will eventually ask you.
| A penetration test for a small business | $5,000–15,000 |
| A day of a senior security consultant | $1,600–4,000 |
| A focused security assessment of one AI application | from $12,000 |
| A SOC 2 readiness programme | $15,000–40,000 |
| One deal stalled on a security questionnaire | your deal size |
| This pack | $299 once |
Those figures are published 2026 market pricing ranges, not quotes, and they vary with scope. To be clear about what this is: the pack does not replace a penetration test or an audit, and it is not a professional assessment of your systems. It is the work you can do yourself, in four weekends, before any of the above would be worth paying for.
One payment, lifetime access
$299 once
Four books, twenty worksheets, twenty-five files. No subscription, no upsell, no second tier.
Buy the packDelivered instantly by email. 7-day refund, no questions asked.
Self-contained HTML files. Open in any browser, phone included, with no connection. Every page has a Save as PDF button. Not a course, not a video, not an app.
No. Those are referenced where relevant, but the books are built around specific documented incidents and the exact configuration change that would have prevented each one. The worksheets are original and several are working code.
You need to have built something that works. If you can configure a workflow in n8n or write a SQL query, you're past the bar. If you've never connected anything, this is too early for you, and the playbook is the better starting point.
No, deliberately. No calls, no community, no coaching. That is what keeps it at this price and delivered instantly. The files are written to be used without me.
The incidents are dated and sourced, so you can see how current they are. The method does not date: permissions, boundaries, retention and isolation do not change when models do. That is the whole argument of the series.
Someone who builds these systems. The proof is that the things inside work, not an income screenshot.
The playbook, not this pack. It covers chatbots, connectors, notetakers, automations and agents for a business that uses AI rather than builds it. See the playbook.
Take the free 10-point exposure check, scored in your browser. Ten questions, two minutes, nothing to install and no email required. Most people score badly and find at least one capability they never meant to grant.