Support & Education For our clients and partners Written for humans, not auditors

Security isn’t
a feature you bolt on.
It’s how you build.

Nobody gets breached during a strategy offsite. It happens on a Friday, through a plugin last updated in 2019, on a server nobody has logged into since the launch party, with a password that also opens someone’s streaming account.

This is the conversation we have with every client before we write a line of code, written down so you can have it without us in the room. No fear-selling and no invented numbers: what actually happens, what happened here at home, and three tools you can work through with your own team.

Go straight to the tools ↓
Free. Ungated. No email wall.
This is the conversation we have with every client, written down and given away. Nothing on this page requires your email address, and the tools never did.

Nobody gets hacked
in the way they imagine.

↳ eight unglamorous ways it actually goes wrong

There is no hoodie. There is no countdown timer. There is an automated scanner working through a list of every site on the internet, looking for a version number it already knows how to open. Most compromises are not clever: they are patient, and they are cheap.

01

The CMS you stopped updating

WordPress runs a very large share of the web, and that very large install base makes vulnerable installations an attractive target for broad automated scanning, not because it is bad software, but because a single working exploit pays off across millions of sites at once. Attackers scan for versions, not for you.

“it still works, though”
02

Plugins with no owner

Outdated and abandoned plugins and themes are a recurring compromise route. Someone installed a slider in 2019, the author moved on, and the code is still running with full access to your database. Nobody removed it because nobody remembers it exists.

“that was the old agency”
03

Set it and forget it

A site launches, the invoice is paid, and the deployment enters a decade of silence. No patch cadence, no monitoring, no alerting, no backup anyone has ever restored. The first person to notice something is wrong is a customer, or a journalist.

“it’s been fine for years”
04

Two-factor, later

Second factors are one of the highest-value controls against password-based account takeover: someone logging in as you with a password they bought. “Later” has been the answer for three years, and the login page does not care about your roadmap.

“it’s annoying on my phone”
05

One password, everywhere

Reuse turns any breach anywhere into a breach of yours. A forum you forgot about in 2016 leaks, and that same password walks into your email, your bank, your CMS admin. Attackers do not guess: they replay.

“but it’s a strong one”
06

The credentials spreadsheet

Shared logins in a spreadsheet, a pinned chat message, or a shared drive folder called Accesos. It is convenient, it is searchable, and it is one compromised laptop away from being the attacker’s index of your entire organization.

“the team needs access”
07

A phone with no lock

The device holding your email, your authenticator, and your session cookies has no biometrics, no passkeys, and a four-digit code shoulder-surfed at a café. Mobile is where your identity lives now. It deserves the same locks as the front door.

“I’d notice if it went missing”
08

The people who left

Ex-employees, ex-vendors, ex-interns: still holding admin accounts, still on the shared inbox, still in the deploy pipeline. Offboarding is a security control, and in most organizations it is a Slack message that nobody actioned.

“we’ll clean that up”

None of this is exotic. Many of these gaps are routine and inexpensive to start fixing, which is exactly why they keep working as an entry point. Others, like replacing a legacy platform or migrating a vendor, are planned work rather than an afternoon. What they have in common is that they are known, and that being busy is how they stay open. Several of them (numbers three, four, five and eight above) are not code at all: they are settings in a Microsoft 365 or Google Workspace admin console that nobody has opened since setup. The ten that matter, with the exact paths, are here →

This is not
someone else’s problem.

↳ three incidents, shown through four affected organizations

You do not have to look at a foreign retailer to understand the stakes. In the last year, Puerto Rico has watched its payment infrastructure, its government agencies, and its property records all get reached. Two of these cards describe the same Evertec event, because Popular was one of the downstream institutions.

May – June 2026 · payments infrastructure

Evertec

Evertec discovered potential unauthorized access on May 13, 2026, involving a third-party support platform, and disclosed it in a Form 8-K filed with the SEC on June 9, 2026.

The exposure included transaction records, some payment card numbers, and some names and contact details, primarily affecting Puerto Rico financial-institution clients and their customers. Public reporting identified proposed federal class actions; we have not verified the current docket count, so treat the number as reported rather than established.

⚠ entry point: a third-party support platform
June 2026 · downstream exposure

Banco Popular

Popular’s customers had data exposed through a third-party provider: the Evertec incident. Popular’s own 8-K states that its systems were not accessed.

That distinction matters, and it is exactly the point. An institution can run its own security well and still have its customers’ information exposed, because the data was sitting in a partner’s environment. Your customers do not experience that nuance. They experience a letter.

⚠ entry point: a vendor holding your customers’ data
November 25, 2025 · government services

TrueNorth

Puerto Rico officials publicly confirmed a ransomware attack involving TrueNorth Corporation, an IT vendor, affecting three government agencies: the Department of Education, ASES, and the CFSE. Officials also said no citizen data was lost.

Beyond that, the detail is reporting rather than a public forensic finding. According to reporting that cited an internal government report, attackers used compromised vendor credentials and more than 150 CFSE servers were affected. We are flagging the sourcing because the distinction matters: one vendor relationship becoming three agencies’ outage is the pattern worth learning from, and it rests on a document nobody outside government has seen.

⚠ reported entry point: compromised vendor credentials
July 2026 · public records

CRIM’s Catastro Digital

CRIM’s Catastro Digital property map exposed roughly one million Social Security numbers, downloadable without any authentication. The hole was patched within days.

The agency denied that a breach had occurred and did not notify the affected citizens. Reported by ProPublica on July 9, 2026.

⚠ entry point: no authentication at all
Source: ProPublica
the pattern, if you squint:

Read the four cards as three incidents. Popular and the three agencies were downstream victims of somebody else’s compromise. Evertec was itself compromised, through a third-party support platform. CRIM was a direct exposure of its own system. The pattern worth taking is the downstream one: a support platform, a vendor’s credentials, a partner’s environment. You inherit the security of every vendor and every platform in your stack: their patch discipline, their access hygiene, their incident response, whether you ever met their engineers or not. Which is the whole argument for knowing exactly what your stack is made of, and owning the parts that hold anything you would hate to lose.

Have you already
been exposed?

↳ ten seconds, no signup, nothing stored

Many addresses appear in known breaches, usually because a service was compromised rather than the account holder: their address, password hash and whatever else went into a file that has been circulating ever since.

Put an email address into the panel. We check it against Have I Been Pwned, the public breach index maintained by security researcher Troy Hunt, and show you exactly what turned up.

honestly: the point of this tool is not the result. It is the moment right after, when you realize a password you still use was in one of these.

Breach lookup

Check an address

Yours, or your organization’s shared inbox. Both are worth knowing.

Privacy: the address is checked against Have I Been Pwned through our own server. We do not save it in application storage or analytics, and we do not add it to any list. Being straight with you about the limit: it does travel through our server to HIBP, and transient operational logs may exist somewhere in that delivery chain, which is not something we can promise away.

Breach data powered by Have I Been Pwned.

A breach isn’t the end
of the harm. It’s the raw material.

↳ what someone can build with what just came back

Whatever that panel returned, the damage of a leak is not the moment it happens: it is everything the data enables afterwards, for years, in the hands of whoever buys it. Records get dumped, aggregated by brokers, cross-referenced with the last eight leaks, and assembled into a profile more complete than anything you would have handed over voluntarily.

And where that profile used to need a human to exploit it slowly, one target at a time, it now feeds tools that write like you, sound like you, and can appear as you on a video call. Yesterday’s leaked password becomes tomorrow’s convincing impersonation.

Email addressesPasswords

Account takeover, everywhere you reused it

Credentials get replayed automatically across hundreds of services. The attacker does not need to break your password: they need you to have used it twice.

Phone numbers

SIM swap and targeted texts

A number tied to your name is a route to your SMS second factor, and a channel for messages that already know who you bank with and who you work for.

Dates of birthGovernment IDs

Identity and credit fraud

The static facts about you never expire and cannot be rotated. Once they are out, they are out, which is what makes an exposure like the CRIM one so hard to undo.

Your public writingPhotosRecorded audio

The impersonation raw material

Never leaked, never stolen, simply published. Your posts, your interviews, your voice on a webinar. Combined with the leaked profile, this is what makes an impersonation of you specific enough to work.

where this goes next, on two other pages:

The personal and the organizational stopped being separate problems. A leaked staff address plus a few public recordings is now enough to place a persuasive, personalized call to your finance team, or to your bank, your colleagues, or your family. The same collapse in cost that made attacking your infrastructure cheap made impersonating your people cheap. The documented cases and the verification protocol are on deepfake-proof your organization; what the same machinery did to family photographs, and what it means for the children in them, is on the kids are already in the dataset. The rest of this page is your own stack.

Two honest
mirrors.

↳ one for you, one for your organization

These are the part of this page we actually care about. Your answers stay in your browser: there is no submit, no email gate, and no lead capture. Our analytics receives the derived result, such as the score, tier, percentage and weakest category, so we know these tools get used and roughly how they land. It does not receive your individual answer selections, any free text, your name, your email address or your organization name. Work through them alone, or better, put them on a screen in a room with your team and argue about the answers. The disagreement is the finding.

Personal hygiene, in eight questions

≈ two minutes

Answer as your honest self, not your aspirational self. The score is worthless if you grade on intentions.

Question 1 of 8

Loading…

Infrastructure posture, in ten items

for whoever signs the contracts

Written for decision-makers, not engineers. “Not sure” is a legitimate and extremely informative answer: in most organizations, uncertainty is the actual finding.

0 of 10 answered
Take it with you

The security
workbook.

Fourteen printable pages you can put on a table with your team and fill in with a pen. No login, no download form, no follow-up sequence: it is yours to copy, adapt, and hand to whoever runs operations. If your ops manager works through it end to end, you will know more about your own organization than most assessments would tell you.

  • → Infrastructure inventory worksheet: what you run, who owns it, when it was last touched
  • → Vendor and access audit tables: who holds keys to what, and why
  • → Password and 2FA migration checklist: a real sequence, in order
  • → Patch calendar: twelve months, one page
  • → Incident-response one-pager: the first hour, written before you need it
  • → Family exposure audit: the one page to take home, not to the office
  • → Puerto Rico compliance quick-check: what binds you, with the statute named
  • → Rights at a checkpoint: the one-pager to fold into a passport
  • → AI policy starter: nine answers and you have a policy
  • → Privacy reset: the settings with evidence behind them
  • → Quarterly review cadence: so this survives past the enthusiasm
Open the workbook → opens with a print button: save as PDF from there
mutiny.
Workbook · 14 pages

Own your stack.

A working session for teams who would rather find their own gaps than be shown them.
bring a pen. seriously.

What the law
actually says here.

↳ written for whoever signs things

Here is the news most people on this island have not caught up with. Between June and August 2026, Puerto Rico went from having no artificial-intelligence statutes to having five. None of them is the sweeping AI compliance regime the headlines might lead you to expect, and understanding exactly where they land is more useful than any general anxiety about regulation.

Puerto Rico artificial-intelligence statutes enacted in 2026
Law Enacted What it does Who it binds
Ley 105-2026 10 Jun 2026 Electoral advertising made or altered with AI must disclose it Campaigns, PACs
Ley 116-2026 18 Jun 2026 Government must tell citizens before an AI interaction and offer a human route; PRITS to regulate within 180 days Government only
Ley 135-2026 15 Jul 2026 Amends Ley 21-2021 on non-consensual intimate imagery to cover wholly AI-generated material; threatening to disclose is a separate felony Any person (criminal)
Ley 140-2026 Jul 2026 Adds AI to mandatory government cybersecurity training Government
Ley 163-2026 2 Aug 2026 Amends Ley 139-2011 so that “image” expressly covers AI-generated, cloned, simulated or altered likeness, voice, movement and gestures Anyone, including private business
the part worth stating plainly, because nobody else does:

As of 15 August 2026, we found no general cross-sector Puerto Rico statute imposing AI-specific disclosure, risk-assessment, bias-audit or deployer duties on a private company merely because it uses AI. The AI-specific enactments highlighted here cover four principal areas: elections, government, criminal deepfakes, and likeness. That is not the universe of law that can govern AI conduct, since consumer, privacy, employment, discrimination and contract law all still apply. If a vendor is selling you an “AI compliance package” for a local private-sector obligation, ask them to name the statute.

Nor are there AI executive orders. PRITS Carta Circular 2023-002, from April 2023, binds the Executive Branch: use reports, and prior PRITS authorization before any agency integrates, acquires or contracts for AI development. That one matters if you build for government clients. P. del S. 68, which would create an AI Officer and advisory committee, passed the Senate in April 2025 and stalled in the House: it is not law. In a single session there were three vetoes and a pocket veto of other AI bills; the Legislature is running ahead of the Governor on this.

What binds you today.

Two obligations already apply to an ordinary Puerto Rico business with a website. Neither is new, neither is about AI in general, and both are routinely missed.

Obligation one

Ley 39-2012 · you must publish a privacy policy

Anyone resident in, or doing business in or from, Puerto Rico who operates a commercial website or online service collecting personal information from PR residents must publish a privacy policy “de una manera clara, concisa, conspicua y no ambigua”: what is collected, the persons or entities with whom it may be shared, how material changes to the policy are announced, and, if you maintain such a process, how someone reviews or changes their information. Whether categories suffice or vendors need naming is a question for counsel on your facts.

The statute’s definition of personal information includes email addresses and ZIP codes as well as fingerprints, voice recordings and retina images. Those items satisfy the personal-information element. The duty applies only when the statute’s other operator, commercial-service and Puerto Rico coverage conditions are also met. Publishing a policy, or a trust seal, that does not correspond to reality is the conduct the statute attaches its $50,000 administrative fine to. Other violations fall under DACO’s general enforcement framework, where the penalty depends on the violation.

If you are a covered operator, a missing privacy policy is a local compliance problem, entirely independent of GDPR or CCPA. Coverage turns on being resident in or doing business in or from Puerto Rico, operating a commercial website or online service, and collecting and maintaining personal information from Puerto Rico residents. It does not automatically reach every business.

Up to $50,000 for policy/practice mismatch
Obligation two

Ley 163-2026 · AI likeness is protected likeness

As of 2 August 2026, Ley 139-2011’s protection of a person’s image expressly covers AI-generated, cloned, simulated or altered likeness, voice, movement and gestures. Unauthorized commercial, mercantile or advertising use of an identifiable person’s AI-generated or cloned likeness may fall inside the statute. Consent and the statutory exceptions are essential elements: a documented authorization changes the analysis entirely.

The damages come from the parent statute, Ley 139-2011, rather than from the 2026 amendment: statutory damages of $750 to $20,000 per violation, up to $100,000 where the conduct is intentional or grossly negligent, plus attorney’s fees, with a one-year statute of limitations. It reaches unauthorized commercial use within Puerto Rico regardless of where the person depicted resides.

Carve-outs exist for news, political expression, non-commercial satire, and people incidentally in the background.

$750–$20,000 per violation · 1-year clock
↳ if anything you run touches people under 18:

Ley 185-2024, the Ley para la Protección de la Privacidad Cibernética de los Niños y Jóvenes, was enacted on 27 August 2024 and took effect on 1 March 2025. It applies to a defined social-network site or application that allows Puerto Rico residents aged 18 or younger to register, rather than to any website with young users, and it includes 18-year-olds. It imposes specialized consent, data-minimization, profiling, geolocation and deletion duties, including account deletion on request within 45 calendar days, enforced by the Negociado de Telecomunicaciones, with civil penalties reported at up to $25,000 per violation. Its preamble and its operative text do not read identically on consent, and the operative provisions permit processing in specified circumstances rather than banning it outright. If you operate something that might meet the definition, this is a statute to take to counsel, not to summarize from a page like this one.

Federal rules moved too. The FTC’s amendments to the COPPA Rule were published on 22 April 2025 and took effect on 23 June 2025, with full compliance required from 22 April 2026 and no extension granted. They add separate parental consent for third-party disclosure and targeted advertising, retention limits with a written published retention policy, a written children’s data security program, and biometric identifiers within the definition of personal information. Enforcement is live: Disney agreed to a $10 million civil penalty on 2 September 2025.

Read all of that against the previous section. Statutes now restrict what may be done with a minor’s data going forward, while the material already absorbed into trained models sits permanently outside the reach of any deletion request.

the one everyone gets wrong:

Ley 111-2005 is Puerto Rico’s breach-notification statute (10 L.P.R.A. §§ 4051–4055, as amended by Ley 97-2008). It reaches government in all branches, any private entity authorized to do business in Puerto Rico, and all educational institutions. The definition of covered data is unusually broad by US standards: it includes usernames, passwords, and employment evaluations.

The correction: the ten-day clock runs to DACO only, and it is improrrogable. There is no fixed deadline for notifying the affected individuals; the statute requires it “de la manera más expedita posible.” You will see “ten days to notify customers” written everywhere. That is not what the statute says. Penalties run $500 to $5,000 per violation, and government breaches go to the Procurador del Ciudadano.

Also live regardless of AI: under Ley 40-2024, contracted information-technology and communications service providers must notify PRITS and the contracting government entity within 48 hours of a qualifying incident. It is a narrower category than “anyone who contracts with the government,” which is how it is usually described. Ley 5-1973 gives DACO a deceptive-advertising prohibition, the local analogue of FTC Act §5, with fines up to $10,000 and each day treated separately. Ley 207-2006 bars employers from displaying employee Social Security numbers.

And federal law is not somewhere else: under 48 U.S.C. § 734, US statutory law has the same force in Puerto Rico. HIPAA’s definitions name the Commonwealth expressly, the TCPA and FTC Act §5 reach territories, and COPPA applies through its operator definition. As of August 2026 there is still no comprehensive Puerto Rico privacy law: comprehensive privacy bills have been introduced in recent sessions but none has been enacted.

And everywhere else you might ship.

Most organizations here serve users beyond the island, which means the binding rule is often somebody else’s. Four worth knowing, each stated at the level of confidence the record supports.

Federal

There is no comprehensive federal AI statute. A proposed moratorium on state AI laws was stripped 99–1 on 1 July 2025. The administration is pursuing preemption through executive action, including a DOJ AI Litigation Task Force created in January 2026, and through litigation such as xAI v. Colorado, where DOJ has moved to intervene. All of it is ongoing; nothing is settled.

Colorado

The Colorado AI Act was repealed and reenacted before it ever took effect, by SB 26-189, signed 14 May 2026. The replacement drops the duty of care, risk-management program and impact assessments, and keeps developer documentation, deployer notice, a 30-day adverse-decision explanation, and access, correction and human-review rights. Enforcement is AG-only, and obligations begin 1 January 2027. Much of the web still says June 2026; that is wrong.

California

SB 942, the AI Transparency Act as amended by AB 853, went live 2 August 2026 for generative-AI providers with over a million monthly California users. AB 853 is the one that controls that date: it delayed the Act’s operation to 2 August 2026, so do not read the operative date off SB 942’s original bill record. What it requires: a public detection tool, latent provenance metadata, and $5,000 per violation per day. From 1 January 2027 large platforms must preserve provenance metadata, which matters for image pipelines and CMS builds. AB 2013 training-data disclosure has been live since 1 January 2026, and carries a trap: fine-tuning someone else’s model can make you a “developer.” SB 243 on companion chatbots carries a private right of action.

European Union

The timeline changed in July 2026. Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force 27 July 2026, delayed the high-risk obligations: Annex III to 2 December 2027, Annex I to 2 August 2028. Article 50 transparency was not delayed and went live on 2 August 2026: chatbot disclosure, deepfake labelling, and machine-readable marking of synthetic content. Under the Act’s extraterritorial scope, it reaches a Puerto Rico studio whenever the output is used in the Union.

so, the short version:

Two cross-cutting obligations highlighted here, which may apply to you, are Ley 39-2012’s privacy-policy duty for covered operators, where a policy that does not match practice carries up to $50,000, and Ley 163-2026’s AI-likeness protection at $750 to $20,000 per violation, up to $100,000 where intentional, on a one-year clock. They are not the only two: Ley 111-2005, Ley 5-1973, your contracts, your sector’s rules and federal law all sit alongside them. The nearest-term external deadlines are the TAKE IT DOWN Act’s 48-hour takedown duty, live since May 2026, and EU Article 50 transparency, applying since 2 August 2026, with transitional treatment for qualifying generative-AI systems already on the market.

Everything else is either narrower than it sounds or not yet in force. That is a far better position to plan from than a vague sense that the rules are closing in.

heads up ↳

This is education, not legal advice. We are a technology studio, not a law firm, and none of the above creates a lawyer-client relationship or accounts for your particular facts. Statutes get amended, regulations get issued, and the four PR laws above are weeks old. Before you act on any of it, talk to your counsel, and if you do not have one on this, that is the first thing to fix.

Support & Education · companion page

Protect your privacy.

Your rights when someone asks you to unlock: police stops, airports and borders, Puerto Rico’s own answer, and why a powered-off phone is a different object. The settled law and the open questions, marked separately.

↳ it grew too big to live inside this page, so we gave it its own

Read it →
Support & Education · companion page

The kids are already in the dataset.

Written for parents: what happened to family photographs when machine learning arrived, what teenagers are facing on their phones this year, why a trained model has no delete key, and the six things that genuinely reduce the exposure.

↳ it used to be a section on this page, and it needed the room

Read it →
Support & Education · dated brief

The AI threat record.

Vibe hacking, PROMPTFLUX and PROMPTSTEAL, the GTG-1002 espionage campaign, and the evaluation that got out onto Hugging Face production infrastructure. Every entry sourced to the organization that disclosed it, and revised as the record grows.

↳ kept separately because it ages differently from the rest

Read it →

Rented stacks
break quietly.

↳ what changes when it’s built for you

Plenty of what the assessment surfaces is yours to fix in an afternoon, and you should. This last section is about the part that is structural, and it is what we do, for the record, in case the answer turns out to be “this platform was never built for what we now need from it.”

A platform assembled from a general-purpose CMS and thirty plugins is a stack you did not design, cannot fully inventory, and do not control the release schedule of. Every plugin is a vendor. Every vendor is a door. Building to spec is not vanity engineering: it is being able to answer, on any given Tuesday, exactly what is running and who is responsible for it.

1

No plugin sprawl

Only code that exists because someone decided it should. Nothing inherited, nothing abandoned, nothing running that no one can explain.

2

Minimal attack surface

Fewer moving parts, fewer public endpoints, fewer third parties holding your data. Every capability you do not ship is a vulnerability you cannot have.

3

Access built for real roles

Permissions modeled on how your organization actually works (who reviews, who publishes, who never should) instead of a generic admin/editor split everyone eventually escalates around.

4

Updates on our watch

Supervised deployments. Dependencies tracked, patches applied, backups verified by restoring them. The opposite of set-and-forget, which is simply: someone is looking.

5

One accountable partner

When something moves at 2am, there is a name attached, not a support queue and a shrug about which vendor owns the failure.

The Fundación Rimas ecosystem

A participation platform and an interactive annual report handling youth enrollment, consent, and measured impact, built to spec, with consent and access modeled on how the foundation actually operates, not on what a plugin allowed.

The Family Navigator platform

A platform serving families through sensitive processes, where the data model and the access design mattered as much as the interface. Minimal surface, defined roles, supervised deployment.

An ecosystem portal for a philanthropic foundation

Under NDA, so it stays unnamed, which is itself part of the practice. A multi-property portal built security-first for an organization whose discretion is a requirement, not a preference.

the honest claim, since you’ll ask:

We will never tell you a system is unhackable. Nobody can, and anyone who does is selling something. What we will claim, and stand behind: a minimized attack surface, supervised deployments, and security-first architecture: decisions made at design time rather than patched in after an incident. Fewer doors, all of them known, all of them watched. That is the difference between a system you own and a system you rent.

↳ when you’re ready to fix what the assessment surfaced

Let’s look at your stack.

Bring us the pages you filled in, the gaps you found, and the thing you would hate to lose. A senior partner will read it and tell you straight what needs doing, including the parts you can handle yourselves.