Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions app/blog/page.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -142,6 +142,10 @@ export default function BlogPage() {
</a>
, former CISO and creator of TopFlow.
</p>
<p className="mt-2 text-xs text-muted-foreground">
Publication dates follow our editorial calendar. &ldquo;Updated&rdquo; notes carry the date of the
correction; engineering dates are in the linked commits and design docs.
</p>
</div>

<div className="mx-auto max-w-6xl px-6 py-8">
Expand Down
2 changes: 1 addition & 1 deletion components/blog/articles/20-dollar-saas-infrastructure.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ export function BudgetSaaSContent() {
return (
<div className="space-y-6 text-muted-foreground leading-relaxed">
<div className="bg-primary/10 border border-primary/20 rounded-lg p-6 my-6">
<h3 className="text-lg font-semibold text-foreground mb-2">Updated June 17, 2026</h3>
<h3 className="text-lg font-semibold text-foreground mb-2">Updated September 27, 2026</h3>
<p className="text-sm">
Fixed two inconsistencies: the &quot;standard stack&quot; heading now matches its itemized total, and the
count of architectural decisions matches the list.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ export function EncryptionBugContent() {
return (
<div className="space-y-6 text-muted-foreground leading-relaxed">
<div className="bg-primary/10 border border-primary/20 rounded-lg p-6 my-6">
<h3 className="text-lg font-semibold text-foreground mb-2">Updated June 17, 2026 — small corrections</h3>
<h3 className="text-lg font-semibold text-foreground mb-2">Updated September 27, 2026 — small corrections</h3>
<p className="text-sm">
The pitch in &quot;The Setup&quot; used to say keys stay in the browser at all times; they&apos;re sent to our
server to run a workflow (never stored), so the sentence now says that. And the Content Security Policy this
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ export function SecurityLayersBlogContent() {
return (
<div className="space-y-6 text-muted-foreground leading-relaxed">
<div className="bg-primary/10 border border-primary/20 rounded-lg p-6 my-6">
<h3 className="text-lg font-semibold text-foreground mb-2">Updated June 17, 2026 — corrections</h3>
<h3 className="text-lg font-semibold text-foreground mb-2">Updated September 27, 2026 — corrections</h3>
<p className="text-sm">
We audited this post against the code. Changes: categories now use the <strong>OWASP Top 10 (2021)</strong>{" "}
numbering (the original mixed 2017 and 2021 names); we removed claims of Zod validation at the API boundary
Expand Down
2 changes: 1 addition & 1 deletion components/blog/articles/gdpr-automation-3-minutes.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ export function GDPRAutomationContent() {
return (
<div className="space-y-6 text-muted-foreground leading-relaxed">
<div className="bg-primary/10 border border-primary/20 rounded-lg p-6 my-6">
<h3 className="text-lg font-semibold text-foreground mb-2">Updated June 17, 2026</h3>
<h3 className="text-lg font-semibold text-foreground mb-2">Updated September 27, 2026</h3>
<p className="text-sm">
The &quot;Security Considerations&quot; list now reads as what it always was — recommendations for your own
deployment — rather than statements about stored reports, and says &quot;TLS 1.2 or later&quot; instead of
Expand Down
2 changes: 1 addition & 1 deletion components/blog/articles/gdpr-compliance-by-design.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ export function GDPRComplianceBlogContent() {
return (
<div className="space-y-6 text-muted-foreground leading-relaxed">
<div className="bg-primary/10 border border-primary/20 rounded-lg p-6 my-6">
<h3 className="text-lg font-semibold text-foreground mb-2">Updated June 17, 2026 — corrections</h3>
<h3 className="text-lg font-semibold text-foreground mb-2">Updated September 27, 2026 — corrections</h3>
<p className="text-sm">
The original version said that not collecting data makes most GDPR requirements &quot;irrelevant&quot;. That
confused <em>storing</em> with <em>processing</em>. TopFlow stores no personal data, but it does process
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ export function OpenSourceSecurityContent() {
return (
<div className="space-y-6 text-muted-foreground leading-relaxed">
<div className="bg-primary/10 border border-primary/20 rounded-lg p-6 my-6">
<h3 className="text-lg font-semibold text-foreground mb-2">Updated June 17, 2026</h3>
<h3 className="text-lg font-semibold text-foreground mb-2">Updated September 27, 2026</h3>
<p className="text-sm">
Removed an unsupported claim (&quot;hundreds of developers&quot; reviewing the code) and added what
transparency looked like in practice this month.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ export function SSRFPreventionContent() {
return (
<div className="space-y-6 text-muted-foreground leading-relaxed">
<div className="bg-primary/10 border border-primary/20 rounded-lg p-6 my-6">
<h3 className="text-lg font-semibold text-foreground mb-2">Updated June 17, 2026 — a bypass we found</h3>
<h3 className="text-lg font-semibold text-foreground mb-2">Updated September 27, 2026 — a bypass we found</h3>
<p className="text-sm">
The guard described here had a gap: IPv4-mapped IPv6 addresses in the hex form the URL parser produces
slipped past it. It&apos;s fixed, and the story is below in &quot;The Bypass Our Tests Couldn&apos;t See&quot;.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ export function DatabaseFreeBlogContent() {
return (
<div className="space-y-6 text-muted-foreground leading-relaxed">
<div className="bg-primary/10 border border-primary/20 rounded-lg p-6 my-6">
<h3 className="text-lg font-semibold text-foreground mb-2">Updated June 17, 2026 — corrections</h3>
<h3 className="text-lg font-semibold text-foreground mb-2">Updated September 27, 2026 — corrections</h3>
<p className="text-sm">
An audit of our own claims against the code found this post overstated a few things. Corrected below:
workflows and API keys <em>are</em> sent to our server when you run a workflow (used in memory, never
Expand Down
16 changes: 8 additions & 8 deletions lib/blog/blog-data.ts
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@ export const blogPosts: BlogPost[] = [
excerpt:
"Most SaaS apps default to storing user data. TopFlow takes the opposite approach: zero server-side data storage. Here's why this privacy-first architecture matters.",
publishedAt: "September 30, 2025",
updatedAt: "June 17, 2026",
updatedAt: "September 27, 2026",
readTime: "3 min read",
category: "Architecture",
author: authorCharlie,
Expand All @@ -64,7 +64,7 @@ export const blogPosts: BlogPost[] = [
excerpt:
"As a former CISO, I don't just talk about security—I implement it. Here's TopFlow's 5-layer defense-in-depth model, how it maps to the OWASP Top 10 (2021), and the gaps that remain.",
publishedAt: "October 14, 2025",
updatedAt: "June 17, 2026",
updatedAt: "September 27, 2026",
readTime: "5 min read",
category: "Security",
author: authorCharlie,
Expand All @@ -85,7 +85,7 @@ export const blogPosts: BlogPost[] = [
excerpt:
"Most companies struggle with GDPR compliance. TopFlow is compliant by design—because it doesn't store any user data on servers. Here's how this radical approach works.",
publishedAt: "October 28, 2025",
updatedAt: "June 17, 2026",
updatedAt: "September 27, 2026",
readTime: "2 min read",
category: "Compliance",
author: authorCharlie,
Expand All @@ -107,7 +107,7 @@ export const blogPosts: BlogPost[] = [
excerpt:
"TopFlow's entire architecture documentation is public. Here's why transparency makes security stronger, not weaker—and how it demonstrates real expertise.",
publishedAt: "November 11, 2025",
updatedAt: "June 17, 2026",
updatedAt: "September 27, 2026",
readTime: "1 min read",
category: "Security",
author: authorCharlie,
Expand Down Expand Up @@ -150,7 +150,7 @@ export const blogPosts: BlogPost[] = [
excerpt:
"AI agent builders that allow HTTP requests are vulnerable to SSRF attacks. Here's how TopFlow prevents them with URL validation, private IP blocking, and allowlist enforcement.",
publishedAt: "December 9, 2025",
updatedAt: "June 17, 2026",
updatedAt: "September 27, 2026",
readTime: "4 min read",
category: "Security",
author: authorCharlie,
Expand All @@ -172,7 +172,7 @@ export const blogPosts: BlogPost[] = [
excerpt:
"Most MVPs cost $500-1,000/month in infrastructure. TopFlow runs on $20/month. Here's the complete stack breakdown and why it's possible without sacrificing quality.",
publishedAt: "December 23, 2025",
updatedAt: "June 17, 2026",
updatedAt: "September 27, 2026",
readTime: "1 min read",
category: "Architecture",
author: authorCharlie,
Expand All @@ -194,7 +194,7 @@ export const blogPosts: BlogPost[] = [
excerpt:
"I added AES-256-GCM encryption to protect BYOK API keys in localStorage. It compiled, tests passed—but every ciphertext was immediately unrecoverable. Here's the silent bug, the fix, and what it teaches about cryptographic code.",
publishedAt: "March 15, 2026",
updatedAt: "June 17, 2026",
updatedAt: "September 27, 2026",
readTime: "7 min read",
category: "Security",
author: authorCharlie,
Expand Down Expand Up @@ -264,7 +264,7 @@ export const blogPosts: BlogPost[] = [
excerpt:
"Manual GDPR data access requests take 4+ hours per request. TopFlow automates the entire process in 3 minutes for $0.044. Here's how the workflow works and how you can customize it for production.",
publishedAt: "December 31, 2025",
updatedAt: "June 17, 2026",
updatedAt: "September 27, 2026",
readTime: "3 min read",
category: "Workflows",
author: authorCharlie,
Expand Down
Loading