Security & Trust · Every door asks

One check at the front isn’t enough.

Security and trust engineering means your systems check who is asking, what they’re allowed to touch and whether it’s still the right time, at each door, instead of trusting anyone who got past the front door.

One stolen badge

MIRA · RESTORER · STAFFMira’s work badge, stolen

Who’s who in the story

In our short film, the museum is your business’s systems, the rooms are your apps and customer details, the badges are passwords and logins (so Mira’s stolen badge is a stolen password), the crates are the ready-made parts your apps use, the visitor book is the personal details you keep, and the sensors are tools that watch your computers. Master keys are admin logins; the locked cabinet, a password vault.

HallFront deskLobbyPaintingsOfficeArchiveVault
Try a room

One check at the front · Vault

Wide open, propped with a mop. A painting leaves under an arm.

Night log

Nothing asked past the front desk.

One check at the front

  1. Front desk: The guard scans the badge. It’s real, so the reader says yes.
  2. Lobby: Open, like every room past the desk.
  3. Paintings gallery: Open. Nobody asks again.
  4. Staff office: Open, with the staff files on the desk.
  5. Archive: Open. Anything inside can walk out.
  6. Vault: Wide open, propped with a mop. A painting leaves under an arm.

Every door asks

  1. Front desk: The guard scans the badge. It’s real, so the reader says yes. That’s the first door, not the last.
  2. Lobby: Open to visitors, like your public website, so it doesn’t ask. Nothing valuable sits here.
  3. Paintings gallery: Asks who you are and whether it’s still your shift. Mira works days, so the door says no.
  4. Staff office: Asks whether it’s still your shift. Mira’s shift ended hours ago, so the door says no.
  5. Archive: Asks whether this badge is allowed in here. A restorer’s isn’t, so it says no.
  6. Vault: Wants two proofs: the badge and a code sent to Mira’s phone. The thief has only the badge.

In your business: one stolen password, and how far it reaches.

Experts file this under: zero trust · least privilege · segmentation

An illustration, not a measurement. No setup makes a break-in impossible. Checks at every door make one harder to pull off and easier to spot. It’s step by step, starting with the doors that matter most.

Watch · 2 min 23 sec

Security & Trust: every door asks

At midnight a thief strolls into a grand museum wearing someone else’s real work badge, and past the front desk nothing asks again. A short, funny story about why every door should ask, and what that means for your apps and data.

Read the story instead
  1. On screenHow did he get in?
  2. NarratorThe thief didn’t break in. The guard scanned the badge and waved him in.
  3. NarratorIt’s Mira’s work badge, like a stolen password. Past the entrance, nobody asks again.
  4. NarratorEvery room, even the vault, wide open. Your apps and customer details? Same problem.
  5. On screenThe next night.
  6. NarratorNight manager Aiko and Sticky, her fussy gecko, change one rule.
  7. AikoEvery door asks.
  8. NarratorNot just the front door. Each door asks: who are you? Allowed in here? Still your shift?
  9. NarratorHe’s back, strolling across the lobby. The next door checks it’s really Mira.
  10. StickyNope. You’re not Mira.
  11. NarratorNobody’s trusted just for being inside. The name for this? Zero trust.
  12. NarratorYour passwords work like badges. The cleaner’s badge opens the broom cupboard, not the vault.
  13. NarratorThe vault wants two proofs, like a password and a phone code. Even Sticky gets asked.
  14. StickyWrong toe. Hang on.
  15. NarratorA new app is like a new wing. Aiko plans the locks first. Sticky tries every one.
  16. NarratorMany apps use ready-made parts from strangers. Here, they come in crates. Who sent this one?
  17. StickyNope. Sender: ‘Not a thief.’
  18. NarratorThe visitor book asks only for a first name. Less written down, less to steal.
  19. NarratorSensors watch the rooms, and your computers can have sensors too. Most nights, nothing. Then one thing is odd.
  20. AikoThat moth... is wearing shoes.
  21. NarratorAiko follows a calm plan. Close that door, call the team, write it down.
  22. NarratorDays later, our thief joins the guided tour, then slips off toward the vault.
  23. StickyNope. Tour’s this way.
  24. NarratorNothing’s thief-proof. But you can be harder to get into, and quicker to notice trouble.
  25. NarratorAlgoshred finds the ways into your apps and data, and locks the riskiest first.
  26. NarratorWe add checks to your team’s daily work, and check again as things change.
  27. NarratorDo your doors ask? Visit algoshred.com, or write to contact@algoshred.com.

The idea in plain words

Four ideas, one rule: every door asks

Each one in everyday words first, then the name experts file it under.

A museum corridor at midnight where every gallery door has its own glowing badge reader and spotlight

Every door asks.

Getting past the front desk shouldn’t open every room. Each door checks who is asking, whether they’re allowed in, and whether it’s still the right time.

Four ideas below, each with the name experts use
  1. 01

    Every door asks, not just the front one

    Each room checks who’s asking, whether they’re allowed in, and whether it’s still their shift, so one stolen badge reaches much less of the building.

    Experts file this under: zero trust, segmentation

    Worth knowing: No setup makes a break-in impossible. Checks at every door make one harder to pull off and easier to spot. “Zero trust” is a way of working, not a product you buy.

    See how far one stolen badge gets
  2. 02

    Badges for tonight, for the rooms the job needs

    People and apps get only the rooms their work needs, only while they need them, with a second proof at the risky doors, and old badges are taken back.

    Experts file this under: identity and access management, least privilege, just-in-time access, two-step sign‑in

    Worth knowing: Tighter badges mean a few more asks at the risky doors, so we keep the everyday doors easy.

    Make a badge for tonight
  3. 03

    Locks drawn into the plans, checks on everyday changes

    Ask how a burglar would get in before you build, add quiet checks to everyday changes, then test the finished building the way a curious burglar would.

    Experts file this under: security by design, DevSecOps, application security testing

    Worth knowing: Checks and tests catch many weak spots, not all of them.

  4. 04

    Check the crates, keep less in the visitor book

    Know which outside parts come in and who sent them, and collect only the personal details you need, shown only to the people who need them.

    Experts file this under: software supply-chain security, privacy by design

    Worth knowing: Dock checks catch many bad crates, not all, and a known sender isn’t enough on its own. Packing lists are kept and re-checked. Laws differ by country, so we work with your legal advisers. Nothing here is legal advice.

    Check a crate at the dock

Badges, not master keys

Make a badge for tonight

Pick who needs a badge. The desk prints one that opens only the rooms that job needs, and you choose how long it lasts.

Left, one check at the front desk and every door behind it open; right, the same hall where each door has its own reader
One check at the frontEvery door asks
Who needs a badge?

The cleaner

Opens

  • Lobby
  • Paintings gallery
  • Broom cupboard

Badge for tonight: Stops working at closing.

Opens the paintings gallery and the broom cupboard. Not the vault.

The drawer of old badges

Old badges: taken back.

Badge for tonight, for the cleaner: the lobby, the paintings gallery and the broom cupboard. The vault stays shut. Stops working at closing.

In your business: each login opens only what that job needs, for as long as it’s needed.

Experts file this under: identity and access management · least privilege · just-in-time access · two-step sign‑in · access reviews

Worth knowing: Tighter badges mean a few more asks at the risky doors, so we keep the everyday doors easy.

Who needs a badge?
The cleanerLobby, Paintings gallery, Broom cupboard
The restorerLobby, Paintings gallery, Staff office, Restoration studio
A delivery driverLoading dock
The night managerLobby, Paintings gallery, Staff office, Archive, Vault
The night-light robot that runs itselfGallery light switches

What comes in

Who sent this one?

Many apps are built partly from ready-made parts made by other people. In the museum, they arrive in crates. Pick a crate, and choose how the dock treats it.

Wooden art crates on a hand trolley at a museum loading dock at night, one seal lit by a torch, a figure waiting outside the gate
Pick a crate
ABCGOES INHOLDFROM: NOT A THIEF

At the dock

  • It came from who it says: doesn’t match
  • The seal is unbroken: not checked
  • The name is really the one you ordered: not checked
  • What’s inside matches the packing list: not checked

Stencilled “From: not a thief”: Wheeled straight back out the gate, unopened.

In your business: the outside parts, add-ons and downloads your apps are built from.

Experts file this under: software supply chain · packing list (SBOM) · signing · provenance

Worth knowing: Dock checks catch many bad crates, not all, and a known sender isn’t enough on its own. Packing lists are kept and re-checked.

Sounds familiar?

The signs one check at the front is doing all the work

If any of these ring true, a stolen password could probably reach further than you’d like.

  • “Once someone’s logged in, they can see pretty much everything.”
  • “People who left last year still have a login somewhere.”
  • “One shared password opens the money side of things.”
  • “Security checks happen at the end, if someone remembers.”
  • “Nobody’s sure which outside parts our apps are built from.”
  • “We collect personal details ‘just in case’, and keep them for good.”

A quick self-check

Eight plain questions. Answer what you can, and we’ll point to where we’d look first.

01If one person’s password leaked today, would it open only that person’s things?
02When someone leaves or changes role, is their access taken back by a routine rather than by memory?
03Do the risky doors (money, customer records, the system your customers use) ask for a second proof, like a code on a phone?
04Are the passwords your apps and scripts use kept out of the code, each with an owner?
05Do checks run on every change to your apps without someone remembering to run them?
06Do you have a list of the outside parts your apps are built from, and a way to hear when one needs a fix?
07Do you collect only the personal details you need, and delete them when you’re done?
08If an odd sign-in happened tonight, would someone notice, and know who to call?

Where we’d look first

Answer any question and the places we’d look first appear here.

Talk it through

Answer “No” or “Not sure” to any question to email the list.

Nothing is stored or sent unless you choose to email it.

What we help with

From the front door to the night watch

Eight pieces of work. Start with the door that worries you most, or bring them together.

Doors and badges

Who can open which door, and for how long.

Make every door ask

A stolen badge reaches less of the building.

We find which rooms matter most, put walls between them and make each door check who is asking, from where and on what device, starting with the riskiest.

Experts file this under: zero trust architecture, segmentation, access without a VPN

Right badges, for the right time

A stolen password alone opens less, and old badges are taken back on a routine.

One sign-in for staff, a second proof at the risky doors, master keys (admin logins) signed out for a task and returned, and a routine that takes badges back when people leave or change roles. Password resets at the help desk get a proper check too.

Experts file this under: identity and access management, single sign-on, two-step sign‑in, passkeys, privileged and just-in-time access, access reviews

Keys held by apps, scripts and AI helpers

Fewer forgotten keys lying around, each with a name and an owner.

Count the passwords and keys your apps, scripts and AI helpers carry, move them out of the code into a locked cabinet (a password vault for apps), give each one an owner, and change them on a routine.

Experts file this under: machine identities, secrets management, secret scanning, agent identity

Also in this area

  • Access that asks at every door, with walls between systems
  • Sign-in, second proofs, and passkeys (signing in with your phone or fingerprint instead of a password)
  • Routines for people joining, moving and leaving, with regular checks of who has access
  • Master keys signed out for a task, and returned
  • Keys held by apps, scripts and AI helpers

Built in, not bolted on

Locks in the plans, and quiet checks on everyday changes.

Draw the locks into the plans

Problems show up earlier, while they are small.

Ask “how would a burglar get in?” before building, and add quiet, well-tuned checks to everyday changes, so teams fix things while the work is fresh.

Experts file this under: threat modelling, DevSecOps, security checks in the delivery pipeline, policy as code

Test the finished building like a curious burglar

Weak spots found in a test rather than in a break-in, with a plain list of what to fix first.

Hands-on testing of your apps and the doors between them, including the parts that talk to AI models, with plain write-ups of what to fix first.

Experts file this under: application security testing, code review, penetration testing, API and AI-app security

Also in this area

  • Threat modelling before building: how would a burglar get in?
  • Well-tuned checks on everyday changes
  • House rules the computer checks (policy as code)
  • Hands-on testing of apps, the connections between them, and AI features

What comes in, what you keep

Know your crates, and keep the visitor book short.

Check the crates at the dock

You have a list of what your software is built from, and where each part came from where it can be traced.

A packing list for each app’s outside parts, checks on the seal and the sender, a watch for lookalike names, and a routine to hear when a part needs a fix.

Experts file this under: software supply-chain security, SBOM, signing, provenance, SLSA, dependency scanning

Collect less, show less, keep it tidy

Less to lose, and plainer answers when customers ask what you hold.

Find where personal details live, collect only what has a stated purpose, show each person only what they need, and delete on schedule or on request.

Experts file this under: privacy engineering, privacy by design, data minimisation, retention

Also in this area

  • Packing lists for software parts (SBOM)
  • Seals, sender checks, and guarded steps where your apps are built and packaged
  • Collect only the personal details you need, and show them only to who needs them
  • Routines to delete personal details on time

The night watch

Notice the odd thing, and know what to do next.

Spot the one odd thing, and respond calmly

Odd things are easier to spot, and a bad night follows a plan.

Sensors on your computers and accounts notice odd sign-ins; we sort what they see so the odd thing stands out, write a calm plan with your team (close the door, call the right people, write it down) and try the plan out together.

Experts file this under: security operations, detection and response, incident response, tabletop exercises

Also in this area

  • Sign-in and activity logging that shows what matters
  • Calm response plans, and practice runs with your team
  • Evidence gathered as you go, for customers, auditors and regulators
  • Coaching, and a named go-to person for security questions in each of your teams

We start from whatever you already use, for example your cloud provider’s sign-in and key services, sign-in services (such as Microsoft Entra ID, Okta or Google), password vaults for apps (such as HashiCorp Vault), tools that seal software parts (such as Sigstore), code and parts scanners, and your log and alert systems.

Blank work badges on gold lanyards above a museum night desk, with a drawer of old badges below

Ways to start

A walk-through of one door

One app or system, who holds its badges, and the crates it takes in.

Badge clean-up

Who has which keys, which old ones to take back, and where a second proof belongs.

Dock check

A packing list of the outside parts in one app, and a routine to keep it fresh.

Walk one door with us

How we work

Walk the building first, then lock the riskiest doors

Five steps in plain words, from the first walk-through to your team running it.

  1. Walk

    Walk the building with you

    We walk the building with you: which doors matter most, who holds which badges, which crates come in and what goes in the visitor book. We talk to the people who run each system, not only to the plans.

  2. Map

    Draw the doors that matter

    We mark the open doors and the old badges on one map, against a checklist or standard you already follow (if any). Then we agree with you a short list of what to fix first, and why.

  3. Lock

    Lock the riskiest doors first

    We tighten the riskiest doors and badges with your teams, usually starting with sign-ins and who holds which keys, one system at a time.

  4. Build in

    Put the checks into everyday work

    We add quiet, well-tuned checks to the way your teams already work, so changes, crates and new features go through the same checks. Problems show up while the work is still fresh. Checks and tests catch many weak spots, not all of them.

  5. Watch & teach

    Watch, and teach your team

    We help sort what the sensors see so the odd thing stands out, write a calm response plan with your team and try it out together, and coach your people to run it. We can stay on to help with the next doors if you prefer.

What you get along the way

  • A map of the doors that matter, and who holds which badge
  • A short list of what to fix first, and why
  • Checks added to how your team builds and releases changes
  • A packing list for each app’s outside parts
  • A calm response plan, tried out with your team
  • Notes and coaching for the people who will run it
A night manager with a torch studies a museum floor plan unrolled on a gallery bench, with closed gallery doors and glowing readers behind

Where it fits

Where it becomes real

Illustrative examples, not customer stories: the kind of work this approach suits.

Retail and e-commerce
A support agent’s leaked password opens the order screen it was made for, not the payment settings, and a second proof guards refunds and account changes.
Financial services
Money-moving systems ask for a second proof, master keys are signed out for the task and returned, and the record of who did what is kept as evidence.
SaaS and product companies
New features go through the same quiet checks, and each release carries a packing list of its outside parts, ready for when a customer asks to see it.
Healthcare
Reception staff see the appointment, not the diagnosis; patient details are shown on a need-to-know basis and deleted on schedule.
Manufacturing and connected products
Devices and the software inside them carry sealed parts and a packing list, so a part that needs a fix can be found across product lines. Some countries now ask product makers to keep such lists (rules differ by country; not legal advice).
Teams adopting AI helpers
AI assistants and agents get their own badges with only the rooms they need, their keys live in the locked cabinet, and what they do is logged like anyone else’s.

Good to know

Questions we are often asked

Plain answers to what owners and tech leads ask first. Something else on your mind?

Ask us directly

What does “zero trust” actually mean?

Nobody is trusted just for being inside. Every door checks who is asking, what they’re allowed to touch and for how long. “Zero trust” is a way of working, not a product you buy.

Will this slow my team down?

The checks run inside normal work, so people aren’t tempted to prop doors open. Tighter badges mean a few more asks at the risky doors, so we keep the everyday doors easy.

Where do we start?

With the door that matters most, usually sign-ins and who holds which keys. A badge clean-up and a second proof at the risky doors are often the smallest useful first steps.

Do we have to replace our tools?

Not usually. We start with what you already have, and add only where it helps.

We’re small. Is this for us?

Yes. Automated attacks try lots of doors at once; they don’t check your size first. The smallest useful version is short: take back old badges, add a second proof where money or customer details live, and keep a list of the outside parts your apps use.

Can you help with audits and regulations?

We help you gather the evidence your auditors, customers and regulators ask for as you go, and explain the gaps in plain words. We don’t promise an audit result. Laws differ by country, so we work with your legal advisers. Nothing here is legal advice.

What about the parts of our apps we didn’t write?

We make a packing list of them, check the seal and the sender where we can, and set up a routine so you hear when one needs a fix. Dock checks catch many bad crates, not all, and a known sender isn’t enough on its own. Packing lists are kept and re-checked.

What happens after the project ends?

Your team keeps the maps, the checks, the packing lists and the calm response plan, and we coach them to run it. We can stay on to help with the next doors if you prefer.

Heard it before?

Myths, answered

Myth: “We have a strong front door, so we’re fine.”

Answer: A real badge in the wrong hands walks straight past a front door that only checks badges, and past it nothing asks again. Every door needs to ask.

Myth: “We’re too small to be a target.”

Answer: Automated attacks try lots of doors at once. They don’t check your size first.

Myth: “Our cloud company looks after all of it.”

Answer: They look after the walls and the wiring. You still decide who gets keys to your rooms, and what’s left lying on the table.

Myth: “Security is a product you buy once.”

Answer: It’s mostly habits and checks: badges reviewed, locks tested, crates checked. Tools help. “Zero trust” is a way of working, not a product you buy.

Myth: “Security slows the team down.”

Answer: Locks drawn into the plan get in the way less than locks bolted on at the end. Tighter badges mean a few more asks at the risky doors, so we keep the everyday doors easy.

Myth: “Privacy is the lawyers’ job.”

Answer: Lawyers say what’s allowed. Engineering decides what gets collected, who sees it and when it’s deleted. Laws differ by country, so we work with your legal advisers. Nothing here is legal advice.