Pirobits · Alberto Sola's newsletter
Cybersecurity for building with AI, without messing things up
Your AI agents write code, run commands, and access your files. But do you know how far they can go and what they're leaving exposed? Each week, I share a practical idea to understand what they do, limit their permissions, and protect what you build, from your machine to production.
One email a week · Free
Cybersecurity for people who build
Getting it to work is just the beginning
An application needs credentials. A server exposes services. An AI agent accesses your files and runs commands. Every decision about how you build also determines what you put at risk.
Working code isn't necessarily secure code. You need to review how it handles data, who can access it, and what becomes exposed when you deploy it to production.
I want to understand those boundaries and how to improve them: what each tool can do, which data it can access, and what happens when something fails. At Pirobits, I share that work through practical examples and the decisions behind them.
Agents that work on your security too
I want agents to become part of how we protect our systems: helping review configurations, spot weaknesses, and keep security up to date, from a homelab to a company's servers.
Getting there takes good processes: knowing what each agent can do, isolating its work in sandboxes, and checking changes before they reach production. I'm exploring how all of that fits into the everyday work of building and maintaining applications.
At Pirobits, I share what I try, the decisions I make, and what I would change, so you can apply those lessons to your own projects.
What we do
Agent permissions, local secrets, and real infrastructure: three articles to start with.
- Security for coding agents: remote, sandbox, and permissions
- 🔐 Manage your .env files securely (local secrets and credentials)
- My blog architecture in 2026: infrastructure for one person

Alberto Sola · Behind Pirobits
Building, protecting, and learning
I've spent more than ten years building products, leading teams, and taking systems to production. I apply that experience and a deep understanding of how systems work to make software, infrastructure, and software development with AI more secure.
I've always cared about building things well and keeping them secure. Now I'm exploring how to put agents to work on that security. At Pirobits, I share what I learn.
More about meIf you need a hand with the security of your agents, applications, or infrastructure, get in touch.