Everything we know,
written down
and handed over.
We kept answering the same questions in the same meetings: about breaches, about what a client owes their users, about what to do when someone asks you to unlock your phone. So we started writing the answers down properly, with sources, and giving them away.
This is the shelf. Free. Ungated. No email wall. Nothing here requires an account or an email address: every page, every tool and the whole workbook open on the spot. Bookmark this page; it is the current index to the library.
The shelf.
↳ thirteen on the shelfSecurity is how you build.
How organizations actually get compromised: the eight boring ways, what happened here in Puerto Rico, a breach check for your own address, and two self-assessments you can run with your team today.
The settings that matter.
Microsoft 365 versus Google Workspace, for whoever owns the admin console. The ten highest-value settings ranked by risk removed per minute, with exact console paths, and the tier walls that decide what you can even turn on.
The AI threat record.
What actually happened once attackers got agents: vibe hacking, PROMPTFLUX and PROMPTSTEAL, the GTG-1002 espionage campaign, and the evaluation that got out onto Hugging Face production infrastructure. Revised as the record grows.
The kids are already in the dataset.
What happened to family photographs when machine learning arrived, what teenagers are facing on their phones this year, and why a trained model has no delete key. Every figure carries its caveat, including the famous ones we think are overstated.
Protect your privacy.
What you can decline when someone asks you to unlock a device (at a traffic stop, at an airport, in Puerto Rico), with the settled law and the genuinely open questions marked separately.
Deepfake-proof your organization.
Convincing synthetic voice and video are increasingly accessible and inexpensive, which weakens the oldest verification method there is: recognizing someone. This is the protocol that supplements it.
The first hour.
A tabletop drill you can run with your team over lunch. Four scenarios, one guided flow, and the decision points where most teams quietly go wrong.
Which PR website rules apply?
A starting checklist for several Puerto Rico statutes that may apply to a business website, and for the coverage questions that decide whether they reach you at all.
Own your stack.
The whole practice on paper: infrastructure inventory, vendor and access audits, a password migration checklist, a patch calendar, a Microsoft and Google settings worksheet, an incident one-pager, a family exposure audit, a Puerto Rico compliance check, and a rights carry-card.
AI at work.
What your staff are already pasting in, what each tool does with it, what has gone wrong in court, and the short list of what Puerto Rico law actually requires.
Who’s watching.
An honest tour of everyday surveillance: data brokers, the location trail, cameras, and whether your phone is really listening. The debunkings are the useful part.
The next CMS is a conversation.
Why the admin panel on your own website was always a trade, what a governed conversation replaces it with, and the four rails that decide whether any of it is safe to hand a marketing team. With a sandbox you can try to break.
Estafas en Puerto Rico.
Written in Spanish, for you and for your parents. The schemes running on this island right now, documented by the banks themselves, and what to do in the hour after the money leaves.
One email,
four times a year.
↳ the only mailing on the whole shelf
Everything here is free to read without giving us anything. The one exception you can opt into: when the AI threat record is re-cut, we will tell you. That is the entire list.
The next revision, by email.
We send the quarterly brief update and nothing else. Unsubscribe any time.
That is the whole subscription: one email when the brief is re-cut, and nothing in between. The next revision goes out when the record changes shape rather than on a schedule we invented.
Wrong address, or changed your mind? Reply to any of it, or write to info@mutiny-labs.com.
How to use this.
↳ it is not a reading listIf you have ten minutesRun the self-check
Start with the Puerto Rico website check, or the breach lookup on the security page. Both produce a list of findings or questions to investigate about your own organization. Neither determines compliance or overall security, which is rather the point: they tell you where to look.
If you have an hour with your teamRun the drill
The first-hour tabletop is designed for exactly that: a room, a screen, and the people who would actually be called. It surfaces disagreements that are much cheaper to have on a Tuesday than during an incident.
If you own the riskPrint the workbook
Fourteen pages, one pen, no software. Work through it with whoever runs operations and you will leave with a structured inventory and a list of questions for your technical and legal advisers.
We are a small studio and we would rather work with organizations that already understand this material. Everything on this shelf is the conversation we would have with you anyway. Writing it down once means we spend the meeting on your actual problem instead.
If something here is wrong, out of date, or unclear, tell us. Several corrections on these pages came from readers.
