Selected work / Products and systems
Show the engineering, not just the screenshot.
A good case study explains the constraint, the alternatives that were rejected, the tradeoff that was accepted and what the evidence showed afterwards. That is more useful than a hero image and a number nobody can check.
What work does TechSteps publish?
We publish case studies where we can show real technical evidence. Today that means the two products we build and operate ourselves, SecAI and StackAttest, because their architecture and results are publicly verifiable. Client case studies are published only with written permission and enough detail to be genuinely useful. We do not publish anonymous testimonials or percentage improvements we cannot explain.
Case studies
- 01 Cybersecurity SaaS
SecAI
Turning raw operating-system evidence into prioritized findings, safe automated response and a workflow a small team can actually run.
- Host agent
- Rust
- Command integrity
- Ed25519 signed
- Response
- Approval gated
- 02 Software assurance platform
StackAttest
Making production readiness verifiable, so a founder, accelerator or buyer can see what was tested and where the remaining risk sits.
- Evidence
- App, source, deps, runtime
- Mapping
- Named standards
- Output
- Public Passport
Our case study standard
What every case study here has to answer.
These are the questions we hold ourselves to before a page gets published. If we cannot answer them honestly, the page does not go up.
- 01 What existed before, and what was actually wrong with it?
- 02 What was the real constraint: budget, uptime, data, deadline, team?
- 03 Why was the problem difficult rather than merely unfinished?
- 04 What alternatives were considered, and why were they rejected?
- 05 What did we change, specifically?
- 06 What evidence shows the outcome, and how was it measured?
- 07 What stayed out of scope, and what is still a known risk?
- 08 What did we learn that changed how we work?
On numbers
Where a figure is measured, we say how. Where it is an estimate, we label it as one. Where a third party published it, we link to the source so you can check it rather than trust us. The SecAI case study cites its public StackAttest Passport, validated 28 August 2026, for exactly that reason.
Bring us the hard part.
The interesting projects usually arrive as a symptom rather than a specification. Tell us what is failing and what has already been tried.