<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Arvanta Cyber Blog</title><link>https://www.arvantacyber.com/blog/</link><description>Security engineering notes from Arvanta Cyber.</description><item><title>Control Plane Security: API Keys, Automation Scope, and Release Risk</title><link>https://www.arvantacyber.com/blog/control-plane-security-review/</link><guid>https://www.arvantacyber.com/blog/control-plane-security-review/</guid><pubDate>Sun, 31 May 2026 08:20:00 GMT</pubDate><description>Control-plane code decides who can operate infrastructure, devices, agents, jobs, integrations, and release gates. Its risks need evidence, not loose alerts.</description></item><item><title>Business Logic Security Review for Product Teams</title><link>https://www.arvantacyber.com/blog/business-logic-security-review/</link><guid>https://www.arvantacyber.com/blog/business-logic-security-review/</guid><pubDate>Sun, 31 May 2026 08:10:00 GMT</pubDate><description>Business logic review focuses on the code paths that decide ownership, state, money movement, quotas, approvals, inventory, and automation scope.</description></item><item><title>Evidence-Backed Security Audit for Business-Critical Code</title><link>https://www.arvantacyber.com/blog/evidence-backed-security-audit/</link><guid>https://www.arvantacyber.com/blog/evidence-backed-security-audit/</guid><pubDate>Sun, 31 May 2026 08:00:00 GMT</pubDate><description>Security teams need findings that can survive review. Evidence-backed audit connects source, transit, sink, failed control, business impact, and decision state before a risk is promoted.</description></item></channel></rss>