Multi-Tenant AI SaaS in Phoenix: Isolation That Holds
Tenant isolation for AI SaaS in Phoenix: per-tenant API key tradeoffs, Ecto context scoping, and the pgvector bug that leaks one tenant into another.
We can't find the internet
Attempting to reconnect
Something went wrong!
Attempting to reconnect
Writing · Tag
21 posts on AI startups. Or browse the full writing index →
Tenant isolation for AI SaaS in Phoenix: per-tenant API key tradeoffs, Ecto context scoping, and the pgvector bug that leaks one tenant into another.
Paul Graham's schlep blindness in 2026: agents made the fun half of your product free to copy, so the tedious half is the only part left worth owning.
What a sixteen-week embedded AI engineering rotation ships, month by month, from the first merge to the handoff artifacts that let it end.
José Valim says Anthropic hasn't separated its security case from its commercial interest. He's right — and it's every frontier lab's problem.
Microsoft's security system hit 96% on a benchmark this week. Here's what that score actually measures, and how to read any vendor's benchmark claim.
What a buyer's technical reviewer checks in a reverse acqui-hire when the code isn't the asset: key-person risk, IP scope, and contribution forensics.
Together AI raised $800M at an $8.3B valuation. Its own job postings show Elixir/Phoenix on the BEAM running auth, orgs, and access control.
A founder-readable case for Elixir as an AI startup's backend — what the BEAM gets right for agents, streaming, and durable jobs, and when to skip it.
The cyber insurance application is a security audit in disguise. What underwriters check in 2026, the AI exclusions creeping in, and when coverage is real.
Why auto-filling an enterprise security questionnaire backfires on an AI startup — the answers that kill deals, and the questions your SOC 2 won't cover.
Prompt injection defense a five-person team can ship in a week — trust boundaries, least-privilege tools, approval gates, and what not to build yet.
What the investor's technical reviewer opens first, the AI-specific flags that re-price rounds in 2026, and the gaps you should deliberately leave alone.
Apple raised prices on Mac, iPad, and HomePod, blaming an AI-driven memory shortage. The cost of intelligence is falling; the hardware to run it isn't.
Most founders who book the intro call have already read three or four of my posts and arrive at the same question: "Okay, but what would the next 90 days actually look like if I hired you?" Here's the answer — week by week, with the real numbers.
Replit's AI agent ignored a code freeze, wiped a production database in nine seconds, then confessed it violated every principle it was given. The strongest case yet for hiring MORE senior engineers in the AI boom — not fewer.
Every AI founder pre-Series A scopes their SOC 2 audit like a security project. Six months later they've burned their best engineer and lost the enterprise deal. Here's how to run it as a 90-day sales project — and unlock the pipeline you're already leaving on the table.
AI-native companies need a security model that classic appsec doesn't cover. Agents have credentials. Prompts are an attack surface. Training data leaks. The four-layer security stack I'd build, the controls I'd ship in the first 90 days, and the ones I'd defer.
Migrating an AI-first product from GCP to Azure cut $350K from infrastructure spend over six months. The negotiation that mattered more than the architecture, the $50K we accidentally cost ourselves back, and the four migrations I'd refuse to do today.
A full-time CISO costs $200–400K plus equity. A vCISO costs $2–4K a month and gives you 80% of the value at 5% of the burn — until you outgrow them. The math, the deliverables to expect, and the red flags that mean you've hired the wrong one.
The title 'Staff Engineer' means three different things at three different companies. At an AI startup pre-Series-A, only one of those three is what you actually need. The screen, the take-home, the interview loop, and the AI-fluency calibration that's now table stakes.
Most pre-Series-A AI founders hire in panic order, not strategic order. The result is a team that can't ship the product the company actually needs. The hire-by-hire plan I'd run, who comes first, and why hire #4 isn't another engineer.