Tools I needed and couldn't find anywhere, usually the hard version. By day I lead Ulaa, a Chromium-based enterprise browser, and the SASE stack built into it, designed and shipped, not integrated. The writing is the part vendors leave out: how enforcement actually works, and what the tradeoffs really cost.
Tools I needed and couldn't find done right, so I built them. I gravitate to the hard ones.
Teach it once, every agent knows it.
The memory is a set of Markdown files the agent reads and maintains. You own them, version them in Git, and carry them between tools. The server is only an adapter, the files are the source of truth.


Your terminal and your coding agents in a browser tab, next to the app they're building.
One small Go binary instead of ttyd plus tmux with seams. PTY sessions survive the tab closing, scrollback replays on reconnect. Loopback-only.

A local-first keystroke and activity tracker for macOS.
Everything you type, organized by app, domain, and directory, searchable and charted, and it never leaves your machine. Password-like input is hashed, not stored.
Back up your phone to a USB drive, simple enough for your parents. I built it for exactly that.
Offline, no cloud, no accounts. Resumable, verified copies, plain language. Built for people who find most apps overwhelming.
A Chrome sync analyzer, a Chrome Enterprise URL-pattern matcher, a child-learning kiosk.
By day I lead Ulaa, a Chromium-based enterprise browser, and I built the full SASE stack inside it from scratch: secure web gateway, ZTNA, CASB, DLP, and remote browser isolation. Designed and shipped, not integrated.
I designed the DLP pipeline, the inline TLS inspection layer, the RBI rendering architecture, and a post-quantum VPN stack for government customers, and I keep a sub-24-hour CVE-to-production pipeline on Chromium. I move between two seats: the architect writing the hard parts in Go, and the product lead owning the roadmap. The hard parts are written up, not bulleted here.
Deep-dives on the blogI write about how enterprise browsers, proxies, and security actually work: the enforcement mechanics, the real tradeoffs, the parts whitepapers and product pages skip. Same voice and audience as my LinkedIn.
Where browser-extension security tooling hits its limits: mandatory screen recording, Chrome sync MDM scoping, incognito bypass, DLP on the page vs the wire.
Two categories holding half of the same buyer's problem. Whoever closes the gap wins more than the extension argument.
SSH solved short-lived, identity-attributed access with a one-page config. RDP needs an Active Directory project. The gap is structural.
What enforcement actually looks like when you merge them.
LinkedIn is where these get posted and reach the enterprise-browser-security crowd. The canonical long-form versions live here, at debkosh.com/blogs.
Read the blogI build things I needed and couldn't find, and I like the ones that are hard. I came up through offensive security and SOC architecture, and for the last few years I've led the team building Ulaa and its SASE stack from scratch. Ten years in, security architecture is still the most interesting engineering I know: you hold adversaries, performance, and product experience in your head at once, and getting any one of them wrong breaks the whole thing.