<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Hyperscale Consulting Blog</title>
    <link>https://hyperscale.consulting/blog</link>
    <description>Practical writing on building secure SaaS, shipping as a non-technical founder, vibe coding security risks, MVP development, and cloud security best practices from the engineers who do it day to day.</description>
    <lastBuildDate>Mon, 24 Aug 2026 18:12:18 GMT</lastBuildDate>
    <item>
      <title>Build your demo and sell, sell, sell</title>
      <link>https://hyperscale.consulting/blog/2026-build-your-demo-and-sell</link>
      <guid isPermaLink="true">https://hyperscale.consulting/blog/2026-build-your-demo-and-sell</guid>
      <pubDate>Fri, 21 Aug 2026 09:00:00 GMT</pubDate>
      <author>Henry Addico</author>
      <description>How we used demo, sell, build to validate our second product — starting with a real problem, a real customer, and a room full of founders willing to tell us what was wrong.</description>
      <category>founders</category>
      <category>mvp</category>
      <category>lean canvas</category>
      <category>validation</category>
      <category>demo</category>
    </item>
    <item>
      <title>When to stop prompting and use the platform</title>
      <link>https://hyperscale.consulting/blog/2026-when-to-stop-prompting-and-use-the-platform</link>
      <guid isPermaLink="true">https://hyperscale.consulting/blog/2026-when-to-stop-prompting-and-use-the-platform</guid>
      <pubDate>Tue, 04 Aug 2026 09:00:00 GMT</pubDate>
      <author>Henry Addico</author>
      <description>The line between what your AI builder should generate and what the platform should handle is the difference between a working app and a security incident waiting to happen.</description>
      <category>vibe coding</category>
      <category>security</category>
      <category>founders</category>
      <category>Lovable</category>
      <category>Supabase</category>
      <category>platform</category>
    </item>
    <item>
      <title>Should you add multi-factor auth to your vibe coded app?</title>
      <link>https://hyperscale.consulting/blog/2026-should-you-add-mfa-to-your-vibe-coded-app</link>
      <guid isPermaLink="true">https://hyperscale.consulting/blog/2026-should-you-add-mfa-to-your-vibe-coded-app</guid>
      <pubDate>Tue, 28 Jul 2026 09:00:00 GMT</pubDate>
      <author>Henry Addico</author>
      <description>A founder asked me whether his login screen was enough. The answer took longer than either of us expected — and it starts with a rule most builders have never heard.</description>
      <category>vibe coding</category>
      <category>MFA</category>
      <category>authentication</category>
      <category>security</category>
      <category>founders</category>
    </item>
    <item>
      <title>What should go in an MVP? The founder&apos;s checklist for what makes the cut</title>
      <link>https://hyperscale.consulting/blog/2026-what-should-go-in-an-mvp</link>
      <guid isPermaLink="true">https://hyperscale.consulting/blog/2026-what-should-go-in-an-mvp</guid>
      <pubDate>Wed, 01 Jul 2026 09:00:00 GMT</pubDate>
      <author>Henry Addico</author>
      <description>A straightforward guide to deciding what makes the cut in your minimum viable product — and what to cut without guilt. Written for founders shipping their first SaaS without a technical background.</description>
      <category>Founders</category>
      <category>MVP</category>
      <category>Vibe Coding</category>
      <category>non-technical</category>
      <category>Saas</category>
    </item>
    <item>
      <title>The micro-SaaS ideas that will get you in trouble</title>
      <link>https://hyperscale.consulting/blog/2026-micro-saas-ideas-non-technical-founder</link>
      <guid isPermaLink="true">https://hyperscale.consulting/blog/2026-micro-saas-ideas-non-technical-founder</guid>
      <pubDate>Tue, 30 Jun 2026 11:00:00 GMT</pubDate>
      <author>Henry Addico</author>
      <description>Every list of micro-SaaS ideas skips the hard part. The best ones handle sensitive data — and that is exactly what makes them dangerous to ship without thinking.</description>
      <category>founders</category>
      <category>micro saas</category>
      <category>ideas</category>
      <category>vibe coding</category>
      <category>non-technical</category>
      <category>data sensitivity</category>
    </item>
    <item>
      <title>MVP development cost in the UK: an honest breakdown for non-technical founders</title>
      <link>https://hyperscale.consulting/blog/2026-mvp-development-cost-uk</link>
      <guid isPermaLink="true">https://hyperscale.consulting/blog/2026-mvp-development-cost-uk</guid>
      <pubDate>Tue, 30 Jun 2026 10:00:00 GMT</pubDate>
      <author>Henry Addico</author>
      <description>What an MVP actually costs to build in the UK in 2026 — DIY with AI tools, a platform like ours, or a full custom build. Real ranges, in pounds, with the hidden costs nobody on the first page of Google bothers to mention.</description>
      <category>founders</category>
      <category>mvp</category>
      <category>cost</category>
      <category>uk</category>
      <category>saas</category>
    </item>
    <item>
      <title>Where SaaS actually costs UK SMEs the most — and it is not the bit on the invoice</title>
      <link>https://hyperscale.consulting/blog/2025-where-saas-actually-costs-uk-smes-the-most</link>
      <guid isPermaLink="true">https://hyperscale.consulting/blog/2025-where-saas-actually-costs-uk-smes-the-most</guid>
      <pubDate>Thu, 20 Nov 2025 09:00:00 GMT</pubDate>
      <author>Henry Addico</author>
      <description>Founders usually point at licence fees when they talk about SaaS costs. The data says the real damage is sprawl, fragmented data, and the security tax on top — not the line you can see on the credit card.</description>
      <category>SaaS</category>
      <category>Cost</category>
      <category>SME</category>
      <category>Security</category>
      <category>Founders</category>
    </item>
    <item>
      <title>From Zero to Secure: Implementing CSP in Hours, Not Days</title>
      <link>https://hyperscale.consulting/blog/2025-from-zero-to-secure-implementing-csp-in-hours-not-days</link>
      <guid isPermaLink="true">https://hyperscale.consulting/blog/2025-from-zero-to-secure-implementing-csp-in-hours-not-days</guid>
      <pubDate>Mon, 06 Oct 2025 08:00:00 GMT</pubDate>
      <author>Henry Addico</author>
      <description>A comprehensive, step-by-step guide to implementing Content Security Policy across modern web platforms. From basic protection to advanced configurations, get your applications secured today.</description>
      <category>CSP Implementation</category>
      <category>Web Security</category>
      <category>Developer Guide</category>
      <category>Security Headers</category>
      <category>XSS Prevention</category>
    </item>
    <item>
      <title>Why 50% of Web Apps Are Vulnerable to XSS (And Yours Might Be Too)</title>
      <link>https://hyperscale.consulting/blog/2025-why-50-percent-of-web-apps-are-vulnerable-to-xss-and-yours-might-be-toos</link>
      <guid isPermaLink="true">https://hyperscale.consulting/blog/2025-why-50-percent-of-web-apps-are-vulnerable-to-xss-and-yours-might-be-toos</guid>
      <pubDate>Wed, 17 Sep 2025 08:00:00 GMT</pubDate>
      <author>Henry Addico</author>
      <description>Over half of web applications lack basic XSS protection through Content Security Policy. While modern platforms enable 5-minute deployments, they leave a critical security blind spot that could cost your business dearly.</description>
      <category>AWS</category>
      <category>Threat Modelling</category>
      <category>Best Practices</category>
      <category>Application Security</category>
      <category>Content Security Policy</category>
      <category>CSP</category>
      <category>XSS Prevention</category>
    </item>
    <item>
      <title>Securing AWS Credentials on Engineer&apos;s Machines with macOS Secure Enclave</title>
      <link>https://hyperscale.consulting/blog/2025-securing-aws-credentials-with-secure-enclave</link>
      <guid isPermaLink="true">https://hyperscale.consulting/blog/2025-securing-aws-credentials-with-secure-enclave</guid>
      <pubDate>Tue, 09 Sep 2025 10:00:00 GMT</pubDate>
      <author>Andy Caine</author>
      <description>Last week, I wrote about the lessons from the Nx package poisoning attack, where malicious package versions were published to npm, silently stealing cloud credential from any developer unlucky enough to download them. Amongst other things, the attack highlighted a problem in how we store and manage AWS credentials on development machines.</description>
      <category>AWS</category>
      <category>Security</category>
      <category>Best Practices</category>
      <category>Supply Chain Security</category>
    </item>
    <item>
      <title>Lessons From the Nx NPM Package Poisoning Attack: Securing Your AWS Environment Against Supply Chain Threats</title>
      <link>https://hyperscale.consulting/blog/2025-lessons-from-nx-package-poisoning-attack</link>
      <guid isPermaLink="true">https://hyperscale.consulting/blog/2025-lessons-from-nx-package-poisoning-attack</guid>
      <pubDate>Wed, 03 Sep 2025 10:00:00 GMT</pubDate>
      <author>Andy Caine</author>
      <description>Last week, attackers poisoned the popular Nx build system on NPM with malicious versions that attempted to steal SSH keys, GitHub tokens, npm tokens, and AWS credentials. For many teams, that&apos;s a nightmare scenario. Let&apos;s look at what this attack tells us about securing AWS accounts against software supply chain threats.</description>
      <category>AWS</category>
      <category>Security</category>
      <category>Best Practices</category>
      <category>Supply Chain Security</category>
    </item>
  </channel>
</rss>