Insights with real data, not opinion.
Short technical notes with market research, cited public data and auditable charts.
Recent technical notes
LLM output prices span 100× — and most SMBs don't notice
The public model catalog in July 2026 shows a 100×+ spread between the most expensive output (GPT-5.6 Sol at $30/1M tokens) and the cheapest competitive one (DeepSeek V4 Flash at $0.28/1M). Anyone running single-vendor is paying the worst price per task — and the quality gain doesn't always justify it.
01 · Read article →OWASP LLM Top 10 (2025): what changes for whoever is integrating AI today
The 2025 OWASP LLM Top 10 brings ten risk classes specific to applications using generative models. It doesn't replace the web Top 10 — it adds to it. In SMBs building AI features, these ten items must become a threat-modeling checklist before the first PR.
02 · Read article →EU AI Act: the real calendar and what it means for Brazilian companies
The AI Act entered force in August 2024 with phased applicability. As of February 2025 prohibited practices apply. By August 2026 most obligations kick in. Brazilian companies selling to the EU or processing EU citizens' data need to decide their posture now — not in 2027.
03 · Read article →AppSec maturity in SMBs: why SAMM 0→3 takes 9 months (not 3 years)
OWASP SAMM measures AppSec maturity on a 0-3 scale per practice. Conventional wisdom says companies take years to climb each level. In SMB practice, with method and focus, the jump from 0-1 to 3 on critical practices fits in 9-12 months.
04 · Read article →Want to go deep on one of these topics?
Tell us the problem and what you've tried. We come back with specific technical material.
