Glasspane: concept to responsible disclosure in ~30 hours
A security scanner for higher-ed software, built fast and used responsibly.
The problem
Higher-education institutions run a long tail of specialized software, much of it niche, under-resourced, and rarely security-tested. That's a bad combination: real student and institutional data behind code that no one is actively probing for flaws.
What we built
Glasspane is a focused security scanner aimed at that gap. We scoped it tightly — find a specific, high-value class of vulnerability well rather than everything badly — and took it from concept to a working scanner in about 30 hours of build time. It's the same discipline we bring to client work: build exactly what's needed to answer the question, then stop.
What we found — and how we handled it
Running Glasspane surfaced real vulnerabilities. We filed three CVEs, one of them rated Highly Critical. Every one went through responsible disclosure: we reported to the affected parties, gave them time to remediate, and coordinated on timing before anything became public.
That last part matters as much as the finding. Discovering a flaw is a technical result; disclosing it responsibly is an ethical one. It's the standard we hold clients to when we consult on responsible AI and security — so we hold ourselves to it first.
Why it's a proof point
- Speed with restraint. ~30 hours to a working, useful tool — because the scope was disciplined, not because corners were cut.
- Security judgment, demonstrated. Real CVEs, including a Highly Critical one, not a hypothetical threat model.
- Ethics in practice. Responsible disclosure end to end — the same bar we consult on.
Bring us the problem.
The first conversation's free — and you'll leave with a concrete take on whether AI even belongs in the solution.