diff --git a/app/blog/page.tsx b/app/blog/page.tsx index 405e7c7..5db2607 100644 --- a/app/blog/page.tsx +++ b/app/blog/page.tsx @@ -142,6 +142,10 @@ export default function BlogPage() { , former CISO and creator of TopFlow.

+

+ Publication dates follow our editorial calendar. “Updated” notes carry the date of the + correction; engineering dates are in the linked commits and design docs. +

diff --git a/components/blog/articles/20-dollar-saas-infrastructure.tsx b/components/blog/articles/20-dollar-saas-infrastructure.tsx index 316a8c0..bfaaae1 100644 --- a/components/blog/articles/20-dollar-saas-infrastructure.tsx +++ b/components/blog/articles/20-dollar-saas-infrastructure.tsx @@ -4,7 +4,7 @@ export function BudgetSaaSContent() { return (
-

Updated June 17, 2026

+

Updated September 27, 2026

Fixed two inconsistencies: the "standard stack" heading now matches its itemized total, and the count of architectural decisions matches the list. diff --git a/components/blog/articles/encryption-bug-aes-gcm-ephemeral-key.tsx b/components/blog/articles/encryption-bug-aes-gcm-ephemeral-key.tsx index d5623ce..5e7b204 100644 --- a/components/blog/articles/encryption-bug-aes-gcm-ephemeral-key.tsx +++ b/components/blog/articles/encryption-bug-aes-gcm-ephemeral-key.tsx @@ -4,7 +4,7 @@ export function EncryptionBugContent() { return (

-

Updated June 17, 2026 — small corrections

+

Updated September 27, 2026 — small corrections

The pitch in "The Setup" used to say keys stay in the browser at all times; they're sent to our server to run a workflow (never stored), so the sentence now says that. And the Content Security Policy this diff --git a/components/blog/articles/five-layers-of-security-owasp-top-10.tsx b/components/blog/articles/five-layers-of-security-owasp-top-10.tsx index e20de45..96447c3 100644 --- a/components/blog/articles/five-layers-of-security-owasp-top-10.tsx +++ b/components/blog/articles/five-layers-of-security-owasp-top-10.tsx @@ -4,7 +4,7 @@ export function SecurityLayersBlogContent() { return (

-

Updated June 17, 2026 — corrections

+

Updated September 27, 2026 — corrections

We audited this post against the code. Changes: categories now use the OWASP Top 10 (2021){" "} numbering (the original mixed 2017 and 2021 names); we removed claims of Zod validation at the API boundary diff --git a/components/blog/articles/gdpr-automation-3-minutes.tsx b/components/blog/articles/gdpr-automation-3-minutes.tsx index 6452040..da5bc28 100644 --- a/components/blog/articles/gdpr-automation-3-minutes.tsx +++ b/components/blog/articles/gdpr-automation-3-minutes.tsx @@ -4,7 +4,7 @@ export function GDPRAutomationContent() { return (

-

Updated June 17, 2026

+

Updated September 27, 2026

The "Security Considerations" list now reads as what it always was — recommendations for your own deployment — rather than statements about stored reports, and says "TLS 1.2 or later" instead of diff --git a/components/blog/articles/gdpr-compliance-by-design.tsx b/components/blog/articles/gdpr-compliance-by-design.tsx index ea23a85..f4cb0e5 100644 --- a/components/blog/articles/gdpr-compliance-by-design.tsx +++ b/components/blog/articles/gdpr-compliance-by-design.tsx @@ -4,7 +4,7 @@ export function GDPRComplianceBlogContent() { return (

-

Updated June 17, 2026 — corrections

+

Updated September 27, 2026 — corrections

The original version said that not collecting data makes most GDPR requirements "irrelevant". That confused storing with processing. TopFlow stores no personal data, but it does process diff --git a/components/blog/articles/open-source-security-transparency.tsx b/components/blog/articles/open-source-security-transparency.tsx index c705b36..5c239f4 100644 --- a/components/blog/articles/open-source-security-transparency.tsx +++ b/components/blog/articles/open-source-security-transparency.tsx @@ -4,7 +4,7 @@ export function OpenSourceSecurityContent() { return (

-

Updated June 17, 2026

+

Updated September 27, 2026

Removed an unsupported claim ("hundreds of developers" reviewing the code) and added what transparency looked like in practice this month. diff --git a/components/blog/articles/preventing-ssrf-attacks-ai-workflows.tsx b/components/blog/articles/preventing-ssrf-attacks-ai-workflows.tsx index 31b4d77..52ee34f 100644 --- a/components/blog/articles/preventing-ssrf-attacks-ai-workflows.tsx +++ b/components/blog/articles/preventing-ssrf-attacks-ai-workflows.tsx @@ -4,7 +4,7 @@ export function SSRFPreventionContent() { return (

-

Updated June 17, 2026 — a bypass we found

+

Updated September 27, 2026 — a bypass we found

The guard described here had a gap: IPv4-mapped IPv6 addresses in the hex form the URL parser produces slipped past it. It's fixed, and the story is below in "The Bypass Our Tests Couldn't See". diff --git a/components/blog/articles/why-i-built-topflow-without-a-database.tsx b/components/blog/articles/why-i-built-topflow-without-a-database.tsx index bf78e28..106bc89 100644 --- a/components/blog/articles/why-i-built-topflow-without-a-database.tsx +++ b/components/blog/articles/why-i-built-topflow-without-a-database.tsx @@ -4,7 +4,7 @@ export function DatabaseFreeBlogContent() { return (

-

Updated June 17, 2026 — corrections

+

Updated September 27, 2026 — corrections

An audit of our own claims against the code found this post overstated a few things. Corrected below: workflows and API keys are sent to our server when you run a workflow (used in memory, never diff --git a/lib/blog/blog-data.ts b/lib/blog/blog-data.ts index 411acb5..e8b8872 100644 --- a/lib/blog/blog-data.ts +++ b/lib/blog/blog-data.ts @@ -42,7 +42,7 @@ export const blogPosts: BlogPost[] = [ excerpt: "Most SaaS apps default to storing user data. TopFlow takes the opposite approach: zero server-side data storage. Here's why this privacy-first architecture matters.", publishedAt: "September 30, 2025", - updatedAt: "June 17, 2026", + updatedAt: "September 27, 2026", readTime: "3 min read", category: "Architecture", author: authorCharlie, @@ -64,7 +64,7 @@ export const blogPosts: BlogPost[] = [ excerpt: "As a former CISO, I don't just talk about security—I implement it. Here's TopFlow's 5-layer defense-in-depth model, how it maps to the OWASP Top 10 (2021), and the gaps that remain.", publishedAt: "October 14, 2025", - updatedAt: "June 17, 2026", + updatedAt: "September 27, 2026", readTime: "5 min read", category: "Security", author: authorCharlie, @@ -85,7 +85,7 @@ export const blogPosts: BlogPost[] = [ excerpt: "Most companies struggle with GDPR compliance. TopFlow is compliant by design—because it doesn't store any user data on servers. Here's how this radical approach works.", publishedAt: "October 28, 2025", - updatedAt: "June 17, 2026", + updatedAt: "September 27, 2026", readTime: "2 min read", category: "Compliance", author: authorCharlie, @@ -107,7 +107,7 @@ export const blogPosts: BlogPost[] = [ excerpt: "TopFlow's entire architecture documentation is public. Here's why transparency makes security stronger, not weaker—and how it demonstrates real expertise.", publishedAt: "November 11, 2025", - updatedAt: "June 17, 2026", + updatedAt: "September 27, 2026", readTime: "1 min read", category: "Security", author: authorCharlie, @@ -150,7 +150,7 @@ export const blogPosts: BlogPost[] = [ excerpt: "AI agent builders that allow HTTP requests are vulnerable to SSRF attacks. Here's how TopFlow prevents them with URL validation, private IP blocking, and allowlist enforcement.", publishedAt: "December 9, 2025", - updatedAt: "June 17, 2026", + updatedAt: "September 27, 2026", readTime: "4 min read", category: "Security", author: authorCharlie, @@ -172,7 +172,7 @@ export const blogPosts: BlogPost[] = [ excerpt: "Most MVPs cost $500-1,000/month in infrastructure. TopFlow runs on $20/month. Here's the complete stack breakdown and why it's possible without sacrificing quality.", publishedAt: "December 23, 2025", - updatedAt: "June 17, 2026", + updatedAt: "September 27, 2026", readTime: "1 min read", category: "Architecture", author: authorCharlie, @@ -194,7 +194,7 @@ export const blogPosts: BlogPost[] = [ excerpt: "I added AES-256-GCM encryption to protect BYOK API keys in localStorage. It compiled, tests passed—but every ciphertext was immediately unrecoverable. Here's the silent bug, the fix, and what it teaches about cryptographic code.", publishedAt: "March 15, 2026", - updatedAt: "June 17, 2026", + updatedAt: "September 27, 2026", readTime: "7 min read", category: "Security", author: authorCharlie, @@ -264,7 +264,7 @@ export const blogPosts: BlogPost[] = [ excerpt: "Manual GDPR data access requests take 4+ hours per request. TopFlow automates the entire process in 3 minutes for $0.044. Here's how the workflow works and how you can customize it for production.", publishedAt: "December 31, 2025", - updatedAt: "June 17, 2026", + updatedAt: "September 27, 2026", readTime: "3 min read", category: "Workflows", author: authorCharlie,