A manual for the work

Patch & Proof helps operators, small teams, and informed readers turn security guidance into manageable work. Each guide starts with a defensive purpose and ends with a way to check whether the work is complete.

We prioritize standards, public advisories, and original technical disclosures. We separate observed facts from attribution and editorial judgment. We do not publish exploit procedures, operational attack instructions, panic headlines, or claims that a product makes an organization secure.

The boundary of this manual

These pages are education and planning resources. They cannot assess a live incident, certify compliance, or replace an organization’s authorized security and response teams. Testing and changes belong within your own systems or a clearly authorized scope.

How to read the evidence

Primary documents support factual statements. Editorial interpretations and suggested exercises are identified as such. A vendor description is evidence of what the vendor says; it is not an independent test. Source checks are dated separately from the events being discussed.

How these pages are made

These launch articles were adapted from the publication’s research material with AI assistance and checked against the linked documents. They are editorial explainers, not reports of original field testing. No individual author credentials or independent test results are claimed.

Corrections & contributions

Send the page URL, the statement in question, and a supporting source through contact. Substantive corrections should be noted on the affected article with their date. To suggest a new document or topic, use source submissions. Submissions are reviewed before any editorial use.