<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Nica Furs</title>
    <description>The latest articles on DEV Community by Nica Furs (@nica_furs).</description>
    <link>https://dev.to/nica_furs</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3476267%2F7dd96255-26e6-48f4-b375-db9df4846ca3.png</url>
      <title>DEV Community: Nica Furs</title>
      <link>https://dev.to/nica_furs</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/nica_furs"/>
    <language>en</language>
    <item>
      <title>AI-Powered LSAT Prep vs. Human Tutoring: Where Education Software Still Falls Short</title>
      <dc:creator>Nica Furs</dc:creator>
      <pubDate>Fri, 25 Sep 2026 13:55:57 +0000</pubDate>
      <link>https://dev.to/nica_furs/ai-powered-lsat-prep-vs-human-tutoring-where-education-software-still-falls-short-359o</link>
      <guid>https://dev.to/nica_furs/ai-powered-lsat-prep-vs-human-tutoring-where-education-software-still-falls-short-359o</guid>
      <description>&lt;p&gt;Artificial intelligence is rapidly changing educational software. AI-powered study platforms can explain concepts, generate practice material, analyze answers, build study schedules, and provide students with assistance almost instantly.&lt;/p&gt;

&lt;p&gt;For LSAT preparation, those capabilities are particularly attractive. Students spend months analyzing arguments, reading difficult passages, reviewing mistakes, and trying to identify patterns in their performance. Software that promises personalized explanations and immediate feedback seems almost ideally suited to the task.&lt;/p&gt;

&lt;p&gt;And in many respects, it is.&lt;/p&gt;

&lt;p&gt;AI can make LSAT preparation more efficient, accessible, and personalized than traditional self-study. But there is an important distinction between software that adapts to a student’s inputs and a human instructor who learns how that particular student thinks.&lt;/p&gt;

&lt;p&gt;That difference reveals both the impressive potential of AI-powered education software and the limitations it still has to overcome.&lt;/p&gt;

&lt;h2&gt;
  
  
  How AI Is Changing Test-Prep Software
&lt;/h2&gt;

&lt;p&gt;Traditional test-prep software was relatively rigid.&lt;/p&gt;

&lt;p&gt;A student completed a lesson, answered predetermined questions, received a score, and moved to the next lesson. Some platforms became more adaptive by changing question difficulty or recommending material based on previous performance, but the underlying system still relied heavily on predefined rules.&lt;/p&gt;

&lt;p&gt;Generative AI has dramatically expanded what educational software can do.&lt;/p&gt;

&lt;p&gt;Modern AI systems can provide explanations in conversational language, answer follow-up questions, generate examples, summarize difficult concepts, compare reasoning approaches, and alter an explanation when a student says the first one did not make sense.&lt;/p&gt;

&lt;p&gt;That makes AI substantially more interactive than earlier generations of test-prep software.&lt;/p&gt;

&lt;p&gt;For an LSAT student struggling to understand sufficient and necessary conditions, for example, an AI system can explain the distinction, provide examples, answer questions about those examples, and present the concept again using different language.&lt;/p&gt;

&lt;p&gt;That is genuine personalization—and a meaningful technological improvement.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Difference Between Adaptive Software and Individual Diagnosis
&lt;/h2&gt;

&lt;p&gt;The harder problem is diagnosis.&lt;/p&gt;

&lt;p&gt;Suppose two students repeatedly miss Necessary Assumption questions.&lt;/p&gt;

&lt;p&gt;An AI-powered platform can identify the shared performance pattern: both students are getting the same category of question wrong.&lt;/p&gt;

&lt;p&gt;But the underlying causes may be completely different.&lt;/p&gt;

&lt;p&gt;One student may consistently misidentify the argument’s conclusion. Another may understand the argument but repeatedly select answers that strengthen it without being genuinely necessary. A third may misunderstand quantifiers. A fourth may know exactly what to do but rush whenever answer choices become abstract.&lt;/p&gt;

&lt;p&gt;The data point—“student misses Necessary Assumption questions”—does not itself explain the cause.&lt;/p&gt;

&lt;p&gt;This is where an experienced LSAT tutor can have an advantage. During a live interaction, the tutor can ask the student to explain every step of the reasoning, interrupt at the point where something stops making sense, test alternative explanations, and determine whether the mistake represents an isolated error or a recurring reasoning habit.&lt;/p&gt;

&lt;p&gt;For education software, replicating that level of diagnosis is considerably harder than generating a good explanation.&lt;/p&gt;

&lt;h2&gt;
  
  
  AI Depends Heavily on the Information the Student Provides
&lt;/h2&gt;

&lt;p&gt;Generative AI responds to prompts.&lt;/p&gt;

&lt;p&gt;That is enormously powerful, but it creates a basic limitation in education: students do not always know what they need to ask.&lt;/p&gt;

&lt;p&gt;A student may believe timing is the problem because they cannot finish a Logical Reasoning section. They might therefore ask an AI system for techniques to answer questions faster.&lt;/p&gt;

&lt;p&gt;But perhaps speed is not the real problem.&lt;/p&gt;

&lt;p&gt;The student may be taking too long because they repeatedly fail to recognize common argument structures. Teaching shortcuts or pacing strategies could address the symptom while leaving the underlying weakness untouched.&lt;/p&gt;

&lt;p&gt;Human instruction can work differently because the teacher is not limited to answering the student’s stated question.&lt;/p&gt;

&lt;p&gt;The instructor can decide that the student’s question is the wrong question.&lt;/p&gt;

&lt;p&gt;That ability—to challenge the initial diagnosis rather than merely respond to it—is one of the harder features for educational software to reproduce.&lt;/p&gt;

&lt;h2&gt;
  
  
  Pattern Recognition Is More Than Performance Analytics
&lt;/h2&gt;

&lt;p&gt;Software is extremely good at tracking data.&lt;/p&gt;

&lt;p&gt;An LSAT platform can record which questions a student misses, how long each question takes, whether performance differs by question category, and whether scores improve over time.&lt;/p&gt;

&lt;p&gt;Those analytics can be extremely useful.&lt;/p&gt;

&lt;p&gt;But performance data and understanding a student’s reasoning are not identical.&lt;/p&gt;

&lt;p&gt;Imagine a student repeatedly chooses answers that are slightly too strong. The underlying issue may appear across Necessary Assumption questions, Reading Comprehension inference questions, and Logical Reasoning questions involving causal conclusions.&lt;/p&gt;

&lt;p&gt;A platform organized primarily around question categories might initially treat those as separate weaknesses.&lt;/p&gt;

&lt;p&gt;An experienced instructor may recognize them as manifestations of the same habit: the student repeatedly accepts conclusions that go beyond what the evidence establishes.&lt;/p&gt;

&lt;p&gt;The more sophisticated educational AI becomes, the better it will get at detecting patterns like this. But doing so reliably requires understanding not only whether an answer was wrong, but why the student believed it was right.&lt;/p&gt;

&lt;h2&gt;
  
  
  Human Tutors Can Observe the Reasoning Process
&lt;/h2&gt;

&lt;p&gt;One-on-one instruction provides another source of information: conversation.&lt;/p&gt;

&lt;p&gt;A tutor can ask:&lt;/p&gt;

&lt;p&gt;“Why did you eliminate this answer?”&lt;/p&gt;

&lt;p&gt;“What exactly is the conclusion?”&lt;/p&gt;

&lt;p&gt;“Where does the argument establish that?”&lt;/p&gt;

&lt;p&gt;“Is that condition necessary or sufficient?”&lt;/p&gt;

&lt;p&gt;“What would happen if this answer were false?”&lt;/p&gt;

&lt;p&gt;Those questions force the student to expose the reasoning behind an answer.&lt;/p&gt;

&lt;p&gt;The tutor can then react immediately.&lt;/p&gt;

&lt;p&gt;If the student’s explanation reveals a misconception, the lesson can change direction. If the student understands the concept but applies it inconsistently, the tutor can test whether the problem occurs elsewhere. If the student is using an inefficient process, the tutor can demonstrate a different one and immediately observe whether it works better.&lt;/p&gt;

&lt;p&gt;This continuous loop—observe, diagnose, intervene, observe again—is one of the defining strengths of personalized instruction.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where AI-Powered LSAT Software Has an Advantage
&lt;/h2&gt;

&lt;p&gt;Human instruction has limitations too.&lt;/p&gt;

&lt;p&gt;A tutor is not available every minute of every day. Individual instruction can be expensive. Students may want immediate help with a question at midnight or a quick explanation while studying independently.&lt;/p&gt;

&lt;p&gt;AI excels in precisely those situations.&lt;/p&gt;

&lt;p&gt;An AI study tool can be:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;available around the clock;&lt;/li&gt;
&lt;li&gt;inexpensive relative to private instruction;&lt;/li&gt;
&lt;li&gt;infinitely patient;&lt;/li&gt;
&lt;li&gt;capable of explaining a concept multiple ways;&lt;/li&gt;
&lt;li&gt;useful for organizing study material;&lt;/li&gt;
&lt;li&gt;effective for brainstorming examples;&lt;/li&gt;
&lt;li&gt;helpful for reviewing terminology;&lt;/li&gt;
&lt;li&gt;capable of providing immediate responses during independent study.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Software can also analyze far more performance data than a human tutor could reasonably remember manually.&lt;/p&gt;

&lt;p&gt;The future of test preparation therefore probably does not require choosing between technology and human instruction.&lt;/p&gt;

&lt;p&gt;The more interesting question is how the two can complement each other.&lt;/p&gt;

&lt;h2&gt;
  
  
  AI Can Make Human Tutoring More Efficient
&lt;/h2&gt;

&lt;p&gt;AI does not merely compete with tutors. It can also make tutoring more productive.&lt;/p&gt;

&lt;p&gt;Students can use software between sessions to organize mistakes, review concepts, maintain study logs, summarize areas of difficulty, and prepare questions.&lt;/p&gt;

&lt;p&gt;That allows live instructional time to focus on higher-value work: diagnosing reasoning problems, correcting misconceptions, developing strategy, and working through difficult material interactively.&lt;/p&gt;

&lt;p&gt;Likewise, tutors can potentially use software-generated performance information to identify patterns more quickly.&lt;/p&gt;

&lt;p&gt;The result can be a hybrid model in which software handles repetitive or information-heavy tasks while the human instructor concentrates on judgment and individualized intervention.&lt;/p&gt;

&lt;p&gt;That division resembles what is happening in many other professional fields. AI handles increasingly sophisticated components of the work without necessarily replacing the human responsible for interpreting the situation and deciding what should happen next.&lt;/p&gt;

&lt;h2&gt;
  
  
  Accountability Is Difficult to Automate
&lt;/h2&gt;

&lt;p&gt;Educational software can send reminders, track streaks, generate schedules, and notify students when they fall behind.&lt;/p&gt;

&lt;p&gt;Those features help.&lt;/p&gt;

&lt;p&gt;But interpersonal accountability operates differently.&lt;/p&gt;

&lt;p&gt;A student who knows another person will review the week’s work may behave differently from a student receiving another automated notification.&lt;/p&gt;

&lt;p&gt;During LSAT tutoring, an instructor can also determine whether the student followed the study plan intelligently rather than merely completing the assigned volume.&lt;/p&gt;

&lt;p&gt;Taking five practice tests is not necessarily productive if the student barely reviews them. Completing hundreds of questions does not guarantee improvement if the same reasoning mistakes are repeated.&lt;/p&gt;

&lt;p&gt;Software can measure activity extremely well. A human instructor can ask whether that activity was actually useful.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Challenge for AI Education Software: Understanding the Learner
&lt;/h2&gt;

&lt;p&gt;The central technological challenge is not generating educational content.&lt;/p&gt;

&lt;p&gt;AI can already generate enormous amounts of it.&lt;/p&gt;

&lt;p&gt;The harder challenge is building a sufficiently accurate model of the individual learner.&lt;/p&gt;

&lt;p&gt;What does this student misunderstand?&lt;/p&gt;

&lt;p&gt;Which errors are connected?&lt;/p&gt;

&lt;p&gt;Which explanation will make sense to this particular person?&lt;/p&gt;

&lt;p&gt;When should the system provide another example, and when should it challenge the student’s underlying reasoning?&lt;/p&gt;

&lt;p&gt;Is the student struggling because of knowledge, execution, timing, attention, confidence, or some combination?&lt;/p&gt;

&lt;p&gt;And perhaps most importantly: does the student’s own description of the problem accurately identify the problem?&lt;/p&gt;

&lt;p&gt;The closer educational AI gets to answering those questions reliably, the closer it gets to reproducing some of the most valuable features of individual teaching.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Human Expertise Still Matters
&lt;/h2&gt;

&lt;p&gt;A highly experienced tutor has accumulated something difficult to encode explicitly: thousands of examples of how students misunderstand the material.&lt;/p&gt;

&lt;p&gt;A mistake that seems unusual to a student may be instantly recognizable to an instructor who has encountered variations of it repeatedly.&lt;/p&gt;

&lt;p&gt;That experience can make diagnosis faster.&lt;/p&gt;

&lt;p&gt;The value of expertise is therefore not simply knowing the correct answer. AI can often provide the correct answer perfectly well.&lt;/p&gt;

&lt;p&gt;The value is recognizing the pattern that produced the wrong one.&lt;/p&gt;

&lt;p&gt;This distinction matters especially on reasoning-intensive exams such as the LSAT, where improvement depends on developing transferable analytical habits rather than memorizing a body of facts.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Future Is Probably Hybrid
&lt;/h2&gt;

&lt;p&gt;AI-powered educational software will continue improving.&lt;/p&gt;

&lt;p&gt;Systems will become better at maintaining long-term context, analyzing student performance, recognizing recurring errors, adjusting difficulty, and providing increasingly individualized feedback.&lt;/p&gt;

&lt;p&gt;Some tasks currently performed by tutors will inevitably become automated.&lt;/p&gt;

&lt;p&gt;But that does not necessarily mean human instruction disappears.&lt;/p&gt;

&lt;p&gt;Instead, the role of the tutor may shift toward the areas where human judgment adds the most value: diagnosis, strategy, motivation, accountability, and understanding the nuances of how an individual student reasons.&lt;/p&gt;

&lt;p&gt;For students, that could be the best outcome.&lt;/p&gt;

&lt;p&gt;Software can provide inexpensive, immediate assistance whenever it is needed. Human instructors can provide deeper intervention when automated help is not enough.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Bottom Line
&lt;/h2&gt;

&lt;p&gt;AI has transformed educational software from a relatively static delivery system into something interactive, responsive, and increasingly personalized.&lt;/p&gt;

&lt;p&gt;That is a major improvement.&lt;/p&gt;

&lt;p&gt;But personalization based on software inputs is not yet identical to being understood by an experienced teacher.&lt;/p&gt;

&lt;p&gt;The hardest part of LSAT instruction is often not explaining why the correct answer is correct. It is determining why a particular student repeatedly reaches the wrong answer—and identifying what needs to change so that the same mistake does not appear again in a different form.&lt;/p&gt;

&lt;p&gt;AI-powered test-prep software is becoming remarkably capable at the first task.&lt;/p&gt;

&lt;p&gt;For now, excellent one-on-one instruction still has an important advantage at the second.&lt;/p&gt;

</description>
    </item>
    <item>
      <title>How Vulnerability Scanners Handle False Positives: One Host or the Whole Fleet?</title>
      <dc:creator>Nica Furs</dc:creator>
      <pubDate>Wed, 23 Sep 2026 09:59:12 +0000</pubDate>
      <link>https://dev.to/nica_furs/how-vulnerability-scanners-handle-false-positives-one-host-or-the-whole-fleet-k6p</link>
      <guid>https://dev.to/nica_furs/how-vulnerability-scanners-handle-false-positives-one-host-or-the-whole-fleet-k6p</guid>
      <description>&lt;p&gt;Here's a scenario that anyone running a version-based vulnerability scanner will recognize.&lt;/p&gt;

&lt;p&gt;A scan comes back with "Apache HTTP Server &amp;lt; 2.4.54" on forty hosts. You open the first one. It's a Debian box. Debian doesn't bump version numbers when it backports a security fix; their own FAQ answers the question "the version number for a package indicates that I am still running a vulnerable version!" with the line "we backport security fixes to the version that was shipped in the stable release." So &lt;code&gt;apache2 -v&lt;/code&gt; says 2.4.52, the patch is in, and the scanner is wrong.&lt;/p&gt;

&lt;p&gt;You click &lt;strong&gt;False positive&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Now the question this whole post is about: what just happened to the other 39?&lt;/p&gt;

&lt;p&gt;Depending on the tool, one of three things. The finding is gone from all 40 rows. Or it's gone from this one row and still sitting on the others. Or it's gone from this row until the next scan, at which point it comes back and asks you again. All three are shipped in products people pay for. The difference between them is a data-modeling decision, and it usually gets made by whoever writes the first version of the issues table, long before anyone designs the button.&lt;/p&gt;

&lt;p&gt;That decision is worth walking through slowly, because the two options produce genuinely different products, and the better-behaved one is the less comfortable to use.&lt;/p&gt;

&lt;h2&gt;
  
  
  The status has to hang off a noun. Which one?
&lt;/h2&gt;

&lt;p&gt;Strip the UI away and a scanner's results are a join between two things:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;a &lt;strong&gt;vulnerability&lt;/strong&gt;: a CVE, a CVSS vector, a title, a description. This is a fact about software in general.&lt;/li&gt;
&lt;li&gt;an &lt;strong&gt;occurrence&lt;/strong&gt;: this host, this port, this protocol, this check, seen at this time. This is a fact about your infrastructure.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A "false positive" button has to write a status somewhere. There are only two candidates, and they produce completely different products.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;-- Model A: the status lives on the vulnerability
CREATE TABLE vulnerability (
  id      serial PRIMARY KEY,
  cve     text,
  title   text,
  status  text   -- open | false_positive
);

CREATE TABLE occurrence (
  id               serial PRIMARY KEY,
  vulnerability_id int REFERENCES vulnerability(id),
  host             text,
  port             int
);

&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Click the button under Model A and you've updated one row. Forty occurrences inherit the change because they never had a status of their own. This is the "gone from all 40" behavior, and it feels great for about a week.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;-- Model B: the status lives on the occurrence
CREATE TABLE vulnerability (
  id      serial PRIMARY KEY,
  cve     text,
  title   text
);

CREATE TABLE occurrence (
  id                serial PRIMARY KEY,
  vulnerability_id  int REFERENCES vulnerability(id),
  host              text,
  port              int,
  proto             text,
  status            text,      -- open | snoozed | fixed | false_positive
  status_set_by     int,
  status_set_at     timestamptz
);
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Under Model B the click updates one occurrence. The other 39 don't know anything happened. If you want the grouped view ("Apache &amp;lt; 2.4.54, 40 hosts") you compute it at read time, which is where it belongs, because a group is a way of looking at data and not a thing that can be true or false.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F2crukp91kuchrkxw32wl.jpeg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F2crukp91kuchrkxw32wl.jpeg" alt="Two identical lists of hosts. In Model A one click greys out every row; in Model B it greys out one" width="799" height="450"&gt;&lt;/a&gt;&lt;em&gt;Same click, same UI. The difference is one foreign key&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Model A keeps getting built
&lt;/h2&gt;

&lt;p&gt;Nobody picks Model A out of carelessness. It gets picked because it matches what you see on screen. The list is grouped by vulnerability, the row you clicked on is the vulnerability, so the status goes on the vulnerability. Obvious.&lt;/p&gt;

&lt;p&gt;And the false positives that hurt the most really are systemic. Version-based detection is wrong on every Debian, Ubuntu, RHEL or SUSE box in the fleet, in the same way, for the same reason. So "make this check shut up" is exactly the button anyone wants in that moment.&lt;/p&gt;

&lt;p&gt;The trouble is that the Debian backport is true on the Debian box and false on the Ubuntu 18.04 box that nobody has touched since 2021. Both show up in the same group. Model A can't tell them apart because it threw that information away the moment you clicked. And the next time someone runs a compliance report, or an attacker runs &lt;code&gt;nmap -sV&lt;/code&gt;, the group boundary you drew in the UI isn't going to mean anything to them.&lt;/p&gt;

&lt;p&gt;A false positive is a claim about a host. Not about a check.&lt;/p&gt;

&lt;h2&gt;
  
  
  How three well-known tools handle it
&lt;/h2&gt;

&lt;p&gt;You can watch this lesson get learned in public, because the fix tends to leave a scar in the config format.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Trivy&lt;/strong&gt; started with &lt;code&gt;.trivyignore&lt;/code&gt;: one CVE ID per line, applied to the whole scan. Global by design. The later &lt;code&gt;.trivyignore.yaml&lt;/code&gt; format adds &lt;code&gt;paths&lt;/code&gt;, &lt;code&gt;purls&lt;/code&gt;, &lt;code&gt;expired_at&lt;/code&gt; and a &lt;code&gt;statement&lt;/code&gt; field for the reason. You can still ignore a CVE everywhere, but the docs now say plainly that without paths or purls the suppression stays global. Scope was bolted on after the flat file turned out to be a blunt instrument.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Greenbone / OpenVAS&lt;/strong&gt; made scope a first-class thing from the start. An override is attached to a host or IP range, a port, a task, and optionally a single result; "False Positive" is just one of the values you can set. If several overrides match, the most specific one wins, and you can give an override a lifetime in days. It's more clicks. It's also impossible to hide a finding fleet-wide by accident.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;DefectDojo&lt;/strong&gt; has a setting called False Positive History: when a new finding comes in and a matching one in the same product was already marked false positive, the new one gets marked automatically. Which is useful, and which is also how you end up with issue #2525 in their tracker, where a user reports that deduplication reopened their false positives on reimport and argues that "the finding should stay inactive." Both sides of that thread are right. That's the tension every one of these tools is stuck with: a false positive that never comes back is a suppression rule with a nicer name, and a false positive that always comes back is a chore.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where Topscan landed
&lt;/h2&gt;

&lt;p&gt;Topscan.me stores the status on the occurrence. Model B.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"It's the part of the data model I'd defend hardest," says Aleksandr Melnichuk, Product Director at Topscan.me. "Everything else in that list is a view you're allowed to change your mind about. The key isn't."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;An issue record is keyed on target + issue type + port + protocol, and the status (open, snoozed, fixed, or false positive) lives on that record. The CVE data is a separate classification object, one-to-many. The product's help center defines a false positive as "a CVE-based finding that is incorrect for this specific target," and that wording was chosen carefully: the word doing the work is this.&lt;/p&gt;

&lt;p&gt;A CVE is a fact about a piece of software. Whether it applies is a fact about one host on one port, and that's the only level where "this is wrong" can honestly be said. Everything above that level is aggregation.&lt;/p&gt;

&lt;p&gt;So the grouping is purely a view. The default issue list shows "Apache HTTP Server &amp;lt; 2.4.54 - 12 occurrences" as one row, because for a posture overview that's the right density. Flip a switch called Triage mode and you get 12 rows, each with its own host and port, with your filters preserved. Every issue's detail panel also lists its occurrences by hostname and port, so you see the full spread before you decide anything. The data underneath doesn't change between the two views. Only the query does.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fdfwyxkqhe01x6dii8c0f.jpeg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fdfwyxkqhe01x6dii8c0f.jpeg" alt="One issue row labelled twelve occurrences, expanded into twelve rows with hostnames and ports." width="799" height="450"&gt;&lt;/a&gt;&lt;em&gt;Same data, two queries. The grouping is a view, not the storage&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Marking an occurrence as false positive takes it out of the security score and out of the SLA clock for that occurrence. The other eleven keep their score penalty and their deadline. Each status change is recorded with who made it and when, so a false positive is a decision with an author rather than a row that quietly disappeared.&lt;/p&gt;

&lt;h2&gt;
  
  
  The part that needs defending
&lt;/h2&gt;

&lt;p&gt;If the next scan detects the same vulnerability on the same target after you've marked it false positive, it comes back into the current list.&lt;/p&gt;

&lt;p&gt;The docs describe this as intentional, and the reasoning fits in one sentence: if something changes on the target and the vulnerability becomes real, you should know.&lt;/p&gt;

&lt;p&gt;The cost is real. For a genuinely persistent false positive, like the Debian backport that will trip a version check on every scan until the package moves to a new upstream release, this means re-triaging the same finding again. That is annoying.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"I've been on the receiving end of it in our own dashboard," Melnichuk says. "We decided we'd rather be asked twice than go quiet on a host that changed underneath us."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The alternative is a mute button, and over eighteen months a mute button does this to a fleet. Someone marks a finding false positive on a box in year one. In year two the box gets rebuilt from an old image, the finding is real now, and the scanner has been told not to mention it. The person who pressed mute has changed jobs. Nobody is wrong, and nobody knows.&lt;/p&gt;

&lt;p&gt;So the false positive is a claim about a host at a point in time, and the scanner is allowed to ask again.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"If anyone knows a cleaner way to tell 'still the same backport' from 'actually vulnerable now' without a human looking at it, I'd like to hear it," Melnichuk says. "We'd ship it."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Questions to ask before you trust the button
&lt;/h2&gt;

&lt;p&gt;Whether you're evaluating a scanner or building the issues table for one, these will tell you which model you're dealing with faster than any feature list.&lt;/p&gt;

&lt;p&gt;Where does the status column actually live? Ask for the schema, or the API shape. If &lt;code&gt;status&lt;/code&gt; sits next to &lt;code&gt;cve&lt;/code&gt;, you have Model A.&lt;/p&gt;

&lt;p&gt;What happens to a false positive on the next scan? "It stays hidden forever," "it comes back," and "it comes back only if the detection details change" are three different products.&lt;/p&gt;

&lt;p&gt;Does marking one host change the score or the SLA for the others? It shouldn't, and in Model A it can't help it.&lt;/p&gt;

&lt;p&gt;Can you switch between grouped and per-host views without losing your filters? If the per-host view is an export, then the grouping is the storage, whatever the UI calls it.&lt;/p&gt;

&lt;p&gt;And who marked it, when? Without an author and a timestamp, a false positive is a decision nobody can revisit.&lt;/p&gt;

&lt;p&gt;The button itself costs one click either way. What it's attached to decides whether you silenced one host or forty.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Quotes come from an interview with Aleksandr Melnichuk, Product Director at &lt;a href="https://topscan.me/vulnerability-management" rel="noopener noreferrer"&gt;Topscan.me&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
    </item>
    <item>
      <title>When AI reaches production, engineering leaders still own the outcome</title>
      <dc:creator>Nica Furs</dc:creator>
      <pubDate>Tue, 22 Sep 2026 09:13:53 +0000</pubDate>
      <link>https://dev.to/nica_furs/when-ai-reaches-production-engineering-leaders-still-own-the-outcome-4gi7</link>
      <guid>https://dev.to/nica_furs/when-ai-reaches-production-engineering-leaders-still-own-the-outcome-4gi7</guid>
      <description>&lt;p&gt;Alexey Tulia, Executive Leader at &lt;a href="https://coinspaid.dev/" rel="noopener noreferrer"&gt;Coinspaid Dev&lt;/a&gt;, discussed the changing role of engineers and CTOs during the AI Impact in Engineering panel at Tech Race Summit 2026 in Warsaw. His remarks centred on the transition towards AI systems that can act through company infrastructure.&lt;/p&gt;

&lt;p&gt;Companies already use AI to help with drafting and analysis. The next stage will connect agents to live systems, from sensitive data to deployment pipelines, allowing them to act. That access raises questions about permissions and who is responsible for each decision.&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;
  
  
  When AI can act in production
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;“The more authority we give machines, the more important accountability becomes,”&lt;br&gt;
 Tulia said.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Consider an AI agent that can prepare and deploy a change to production. Should it be allowed to do so without human approval? Who is responsible if the deployment fails?&lt;/p&gt;

&lt;p&gt;Before granting that access, the organisation needs permission controls and audit logs. It must also be able to stop the agent and recover from a failed deployment. Together, these requirements reflect Tulia’s broader argument: greater autonomy in production requires clearly defined authority and human responsibility.&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;
  
  
  Investing in the ability to change
&lt;/h2&gt;

&lt;p&gt;Tulia encouraged CTOs to tie AI spending to a specific organisational need. His priorities included strong APIs and reliable data. Automated testing, observability, security and flexible architecture give companies room to introduce new technology safely.&lt;/p&gt;

&lt;p&gt;Engineering teams also need capacity for experimentation. A roadmap that consumes all available resources leaves little room to test an emerging tool or respond when priorities shift.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Architecture and reduced vendor lock-in may generate little immediate revenue. They make it easier to replace a provider or revise a system when assumptions change.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“I don’t need to predict the future perfectly. I need to make being wrong cheap,”&lt;br&gt;
 Tulia said.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Engineers take responsibility for outcomes
&lt;/h2&gt;

&lt;p&gt;AI is speeding up coding and prototyping. Tulia said this should give engineers more room to understand the business problem and follow the result into production.&lt;/p&gt;

&lt;p&gt;Leaders can support that shift by giving teams the business context and a clear expected outcome. Productivity can then be assessed through correctness, maintainability, security and operational performance rather than code volume.&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;
  
  
  Looking towards 2029
&lt;/h2&gt;

&lt;p&gt;Tulia expects smaller engineering teams to manage larger areas of responsibility by 2029. He also expects AI to generate a majority of production code, increasing the importance of verification and technical judgment.&lt;/p&gt;

&lt;p&gt;The CTO role will continue to require deep technical expertise alongside business understanding. Easier technology creation will bring more vendors and AI-generated systems into the organisation.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“I think technical judgment becomes even more important,”&lt;br&gt;
 Tulia said.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;For engineering leaders, the immediate task is to define safeguards and ownership before AI agents receive access to critical production systems.&amp;nbsp;&lt;/p&gt;

&lt;h2&gt;
  
  
  About Coinspaid Dev
&lt;/h2&gt;

&lt;p&gt;Coinspaid Dev is an independently owned and operated software engineering company specialising in blockchain infrastructure development. With more than 120 engineers and over 11 years of industry experience, Coinspaid Dev brings together software engineering, infrastructure, security and R&amp;amp;D teams with experience building distributed systems and blockchain infrastructure operating across more than 20 blockchain networks.&amp;nbsp;&lt;/p&gt;

</description>
    </item>
    <item>
      <title>How to Remove a Watermark From Video You Own the Rights To</title>
      <dc:creator>Nica Furs</dc:creator>
      <pubDate>Fri, 18 Sep 2026 13:47:06 +0000</pubDate>
      <link>https://dev.to/nica_furs/how-to-remove-a-watermark-from-video-you-own-the-rights-to-3ln8</link>
      <guid>https://dev.to/nica_furs/how-to-remove-a-watermark-from-video-you-own-the-rights-to-3ln8</guid>
      <description>&lt;p&gt;Start with the part that decides whether the rest of this applies to you. Removing a watermark is a legitimate edit when the footage is yours, when you bought a stock license that permits the edit, or when the rights holder has cleared it. Taking a mark off a clip you found online is not an edit — it is stripping attribution from someone else's work, and it violates the terms of the platform it came from as well as the copyright underneath. The Overchat AI tool page draws the same line: fine on your own video or under a license that allows editing, potentially unlawful on copyrighted work you do not own.&lt;/p&gt;

&lt;p&gt;With that settled, the useful question is mechanical. Why does the same tool produce an invisible result on one clip and a smeared rectangle on the next?&lt;/p&gt;

&lt;h2&gt;
  
  
  Nothing is being lifted off
&lt;/h2&gt;

&lt;p&gt;The mental model people bring is a sticker being peeled away, revealing what was underneath. That is not what happens. The pixels behind a burned-in watermark are gone — the file never held them. What a removal tool does is decide what should plausibly be there and paint it in.&lt;/p&gt;

&lt;p&gt;ScreenApp describes its own pipeline in exactly these terms: it scans frames to locate the watermark region, builds a mask (auto, with a brush for manual correction), then inpaints the masked pixels using context from the surrounding frames. That last detail matters more than it sounds. A still image can only borrow from the pixels around the hole. Video can also borrow from time — if the camera moved even slightly, a frame two seconds earlier may contain the wall that is currently hidden. Good results often come from that temporal borrowing rather than from clever guessing.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why some marks vanish and others leave a ghost
&lt;/h2&gt;

&lt;p&gt;Four properties of the footage decide the outcome, and none of them are about the tool.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F5fixeg8xzzl8ipfj6u4y.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F5fixeg8xzzl8ipfj6u4y.png" alt="The same removal engine on two different clips: what makes one repaint invisibly and the other leave a smear." width="579" height="247"&gt;&lt;/a&gt;&lt;br&gt;
&lt;em&gt;The same removal engine on two different clips: what makes one repaint invisibly and the other leave a smear.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Static versus moving.&lt;/strong&gt; A fixed corner logo gives the tool one region to solve. A mark that drifts, bounces or animates has to be tracked, and tracking error shows up as a rectangle that shimmers slightly out of sync with the footage.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Opaque versus semi-transparent.&lt;/strong&gt; An opaque logo is a clean hole. A translucent overlay is worse, because the real image is still faintly present underneath, blended with the mark. Remove it and the edges of the blend often survive as a faint patch. The Overchat AI page is straight about this trade: translucent overlays and moving logos can be tracked and removed, while large animated marks over detailed or fast-moving footage may leave traces.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Flat versus detailed background.&lt;/strong&gt; A sky, a plain wall, a shallow-depth-of-field blur — there is almost nothing to invent, so the fill is convincing. Brick, foliage, a bookshelf, text on a sign: the model has to fabricate structure, and structure it invents will not match frame to frame.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Occlusion.&lt;/strong&gt; Media.io names this one plainly in its own limitations: heavy motion blur, fast camera movement and frequent occlusion all reduce effectiveness. When a hand crosses the masked region, the tool is being asked what is behind a hand and behind a logo at once.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fmipt9i6k61vovsitiuia.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fmipt9i6k61vovsitiuia.png" alt="Screenshot: overchat.ai/ai-tools/video-watermark-remover, September 2026" width="800" height="500"&gt;&lt;/a&gt;&lt;br&gt;
&lt;em&gt;Screenshot: overchat.ai/ai-tools/video-watermark-remover, September 2026&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The cost you pay in quality
&lt;/h2&gt;

&lt;p&gt;There are two separate hits, and they get confused. The first is local: the repainted region is invented, so it is softer or more uncertain than the footage around it. The second is global: writing a new video file means encoding again, on top of whatever compression the source already carried. Two lossy passes stacked is visibly worse than one.&lt;/p&gt;

&lt;p&gt;Tools differ here in a way worth checking. The Overchat AI &lt;a href="https://overchat.ai/ai-tools/video-watermark-remover" rel="noopener noreferrer"&gt;Video Watermark Remover&lt;/a&gt; page states it redraws only the part of the frame the watermark covers and leaves everything else alone, and keeps the original resolution. &lt;/p&gt;

&lt;p&gt;ScreenApp goes further and claims it reconstructs from surrounding pixels while skipping re-encoding, so resolution, color, bitrate and audio sync are unchanged. Whether that holds on your particular file is something you verify by looking, not by trusting the copy.&lt;/p&gt;

&lt;p&gt;The practical consequence: do every other edit first. Color, speed ramps, crops, stabilization — all of it before the removal pass, so the removal is the last encode rather than the middle of a stack.&lt;/p&gt;

&lt;h2&gt;
  
  
  Matching the tool to the file you actually have
&lt;/h2&gt;

&lt;p&gt;Limits are where these tools separate, and they separate hard. A 3-minute interview and a 12-second product loop are not the same job.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tool&lt;/th&gt;
&lt;th&gt;Supported formats&lt;/th&gt;
&lt;th&gt;File / duration limit&lt;/th&gt;
&lt;th&gt;Removal method&lt;/th&gt;
&lt;th&gt;Usage / rights&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Overchat AI Video Watermark Remover&lt;/td&gt;
&lt;td&gt;MP4, MOV, WebM&lt;/td&gt;
&lt;td&gt;60 MB, around 16 seconds&lt;/td&gt;
&lt;td&gt;Automatic detection, one button&lt;/td&gt;
&lt;td&gt;Fine on your own video or under a license that allows editing&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ScreenApp&lt;/td&gt;
&lt;td&gt;MP4, MOV, AVI, WebM&lt;/td&gt;
&lt;td&gt;2 GB, output up to 4K&lt;/td&gt;
&lt;td&gt;Auto mask, brush to correct it&lt;/td&gt;
&lt;td&gt;Own footage, licensed stock, public domain, or cleared by the rights holder&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Media.io AI Video Eraser&lt;/td&gt;
&lt;td&gt;MP4, MOV&lt;/td&gt;
&lt;td&gt;Up to 15 minutes&lt;/td&gt;
&lt;td&gt;Brush the object, adjust the timeline as it moves&lt;/td&gt;
&lt;td&gt;Not stated on the tool page&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The trade in that table is real. The one-button route asks nothing of you and gives you no control; the brush route takes longer and lets you fix a mask the detector got wrong. Neither is better in the abstract.&lt;/p&gt;

&lt;p&gt;350,000+ people use Overchat AI, which is where that first tool lives — an all-in-one app with 150+ purpose-built tools spanning image, video, audio and text, running models from GPT, Claude, Gemini, Grok, Kimi and Qwen, on web, iOS and Android. Pro is $14.99 monthly or $59.99 annually; the free plan covers 20 messages a day to basic models plus limited trial image generation. Line that up against ChatGPT Plus at $20, Claude Pro at $20 and Google AI Pro at $19.99 — about $59.99 a month for the trio.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F5kgii6nbtg6e588eu9v4.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F5kgii6nbtg6e588eu9v4.png" alt="Screenshot: screenapp.io, September 2026&lt;br&gt;
" width="800" height="500"&gt;&lt;/a&gt;&lt;br&gt;
&lt;em&gt;Screenshot: screenapp.io, September 2026&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  A method that saves you a bad export
&lt;/h2&gt;

&lt;p&gt;The order below is boring and it works. The first item is the one that gets skipped, and it is the one that saves the whole job.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fl2x6dkz5h7i78bgk98b3.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fl2x6dkz5h7i78bgk98b3.png" alt="The sequence that avoids the two common outcomes: an unusable export, and a removal you had no right to run." width="394" height="355"&gt;&lt;/a&gt;&lt;br&gt;
&lt;em&gt;The sequence that avoids the two common outcomes: an unusable export, and a removal you had no right to run.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Look for the master before anything else. A watermark on an export usually means a clean version exists somewhere — the source file before your editor stamped it, the project timeline, the stock download at the licensing tier that omits the mark. Re-rendering from source is not a better removal; it is not a removal at all, which is why it always wins.&lt;/p&gt;

&lt;p&gt;If the master is genuinely gone, check the file against the ceiling before uploading. A 16-second limit is short enough that a talking-head clip will not fit, and a 60 MB cap can be breached by a few seconds of high-bitrate 4K. Trim to the segment you need, or pick the tool built for long files.&lt;/p&gt;

&lt;p&gt;Then review at full size. A repaint that looks fine in a preview thumbnail can be obvious on a phone screen at full brightness. Scrub the masked region specifically, at normal speed and then frame by frame, and watch for the shimmer that gives away frame-to-frame inconsistency.&lt;/p&gt;

&lt;h2&gt;
  
  
  When the answer is to stop
&lt;/h2&gt;

&lt;p&gt;Some clips will not clean up. A semi-transparent mark stretched across a moving, detailed scene is close to unsolvable, and a fifth attempt with a different tool tends to trade one artifact for another. At that point the honest options are to crop, to cover the area with your own graphic, to re-shoot, or to license a clean copy.&lt;/p&gt;

&lt;p&gt;And the version of stopping that matters most: if the footage is not yours and nobody has cleared the edit, the answer is not a better tool. It is permission, or a different clip.&lt;/p&gt;

</description>
      <category>videowatermarkremover</category>
      <category>videoproduction</category>
      <category>postproductionblog</category>
      <category>contentopspublication</category>
    </item>
    <item>
      <title>When a firmware bug leads to millions in stolen Bitcoin: what the Coldcard incident teaches us about SSDLC and random number generation</title>
      <dc:creator>Nica Furs</dc:creator>
      <pubDate>Wed, 05 Aug 2026 09:52:21 +0000</pubDate>
      <link>https://dev.to/nica_furs/when-a-firmware-bug-leads-to-millions-in-stolen-bitcoin-what-the-coldcard-incident-teaches-us-2hag</link>
      <guid>https://dev.to/nica_furs/when-a-firmware-bug-leads-to-millions-in-stolen-bitcoin-what-the-coldcard-incident-teaches-us-2hag</guid>
      <description>&lt;p&gt;On the night of July 31, approximately 500 Coldcard hardware wallet owners reportedly lost a combined 594.48 BTC (worth around $38.2 million) after attackers exploited a vulnerability affecting seed phrase generation. The incident was first highlighted by blockchain analytics platform Lookonchain.&lt;/p&gt;

&lt;p&gt;Following the reports, Coinkite, the company behind Coldcard, acknowledged that the issue was related to the wallet firmware and warned users to update affected devices immediately. While the company stopped short of confirming that customer wallets had been directly compromised, it admitted that certain firmware versions could generate vulnerable recovery seeds.&lt;/p&gt;

&lt;p&gt;According to Coinkite, the flaw affects all Mk3 firmware versions starting with 4.0.1. It also impacts seed phrases generated on Mk4 and Mk5 devices running firmware earlier than version 5.6.0, as well as Coldcard Q devices prior to version 1.5.0Q. Users were urged to update their firmware and migrate funds generated using potentially affected seed phrases.&lt;/p&gt;

&lt;p&gt;The Coldcard incident raises two critical cybersecurity questions:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;How can weaknesses in the Secure Software Development Lifecycle (SSDLC) result in multi-million-dollar financial losses?&lt;/li&gt;
&lt;li&gt;Why is cryptographically secure random number generation essential for protecting private keys and seed phrases?&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  How a firmware bug turned into a multi-million dollar theft
&lt;/h2&gt;

&lt;p&gt;The Coldcard incident demonstrates that a hardware wallet does not need to be "hacked" in the traditional sense for users to lose their funds. Sometimes, the weakest link isn't the blockchain itself, it's the software used to generate the wallet's cryptographic secrets.&lt;/p&gt;

&lt;p&gt;Public reports indicate that the vulnerability affected seed phrases generated on Coldcard Mk3 devices running firmware 4.0.1 and later, as well as newer models until patched firmware versions became available. Users were advised to update immediately and move their assets to wallets created with secure firmware.&lt;/p&gt;

&lt;p&gt;Although estimates of the total damage vary, publicly available reports consistently mention hundreds of stolen Bitcoin, losses worth tens of millions of dollars, and approximately 500 affected wallets.&lt;/p&gt;

&lt;p&gt;From an SSDLC perspective, the issue was never just a single programming bug. The larger problem is that a security-critical cryptographic function appears to have passed through development, testing, and release without sufficient verification.&lt;/p&gt;

&lt;p&gt;If rigorous validation of entropy sources, regression testing, and independent security reviews are missing during development, a flaw in seed generation can silently make its way into production. For products designed to protect digital assets, even a seemingly minor defect can translate directly into catastrophic financial losses.&lt;/p&gt;

&lt;p&gt;In a mature Secure Software Development Lifecycle (SSDLC), security should be integrated into every stage of development, from requirements gathering and architecture design to code review, testing, deployment, monitoring, and incident response.&lt;/p&gt;

&lt;p&gt;Based on publicly available technical analyses, the Coldcard issue originated in the firmware's key generation process is a component that should arguably receive the highest level of cryptographic scrutiny. When security depends on a random number generator, traditional unit tests alone are not enough. Teams should also implement property-based testing, dependency verification, threat modeling, and independent security audits.&lt;/p&gt;

&lt;p&gt;The practical lesson for security architects and software engineers is straightforward: any code involved in generating private keys, seed phrases, nonces, digital signatures, or entropy should be treated as a maximum-risk component.&lt;/p&gt;

&lt;p&gt;This means introducing dedicated security gates, prohibiting silent fallback mechanisms, and continuously verifying that the device is actually using its intended source of true randomness instead of unintentionally relying on a software-based pseudo-random number generator. Otherwise, even a well-designed product can become a long-term vulnerability waiting to be exploited.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where the SSDLC breaks down
&lt;/h2&gt;

&lt;p&gt;The Coldcard incident highlights a fundamental SSDLC principle: security failures are rarely caused by a single bug, they are usually the result of weaknesses throughout the development lifecycle.&lt;/p&gt;

&lt;p&gt;For security-critical products, every phase of development should include rigorous controls. Requirements should clearly define cryptographic assumptions, architectural reviews should validate trust boundaries, code reviews should focus on security-sensitive components, and testing should extend beyond functionality to verify the integrity of cryptographic operations.&lt;/p&gt;

&lt;p&gt;Public analyses of the Coldcard vulnerability suggest that the issue originated within the firmware's seed generation mechanism. This is precisely the type of functionality that demands the strictest level of scrutiny. A component responsible for generating wallet seeds should never rely solely on conventional unit testing. Instead, development teams should implement property-based testing, dependency verification, threat modeling, and independent security audits to ensure that cryptographic guarantees hold under all conditions.&lt;/p&gt;

&lt;p&gt;For organizations building wallets, HSMs, or any product handling cryptographic secrets, the takeaway is clear: any code responsible for private keys, recovery seeds, nonces, digital signatures, or entropy generation must be treated as a high-risk security boundary.&lt;/p&gt;

&lt;p&gt;Dedicated security gates should be enforced before release. Silent fallback mechanisms should be prohibited, and automated verification should continuously confirm that the intended hardware entropy source is actually being used rather than an unintended software-based pseudo-random number generator (PRNG).&lt;/p&gt;

&lt;p&gt;Without these safeguards, even an otherwise mature product can carry a hidden vulnerability that remains dormant until attackers discover and exploit it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why random number generation is everything
&lt;/h2&gt;

&lt;p&gt;The security of a cryptocurrency wallet ultimately depends on one simple principle: a private key must be impossible to predict.&lt;/p&gt;

&lt;p&gt;That unpredictability comes from entropy, the randomness used to generate seed phrases and cryptographic keys.&lt;/p&gt;

&lt;p&gt;According to public analyses of the Coldcard incident, the firmware bug significantly reduced the amount of entropy available during seed generation. Some reports estimate that entropy dropped to approximately 40 bits on affected Mk3 devices and around 72 bits on other impacted models, far below the level expected for securely generated wallet seeds.&lt;/p&gt;

&lt;p&gt;The practical implication is enormous.&lt;/p&gt;

&lt;p&gt;Instead of facing an astronomically large search space that would be computationally impossible to brute-force, an attacker only needs to search through a dramatically smaller set of potential keys. Given sufficient computing resources and time, what should be a theoretical impossibility becomes a feasible offline attack.&lt;/p&gt;

&lt;p&gt;This class of vulnerability is particularly dangerous because nothing appears unusual to the user.&lt;/p&gt;

&lt;p&gt;The wallet still generates a recovery phrase.&lt;/p&gt;

&lt;p&gt;The familiar list of words is displayed.&lt;/p&gt;

&lt;p&gt;The overall user experience remains unchanged.&lt;/p&gt;

&lt;p&gt;Yet beneath the interface, the cryptographic foundation has already failed.&lt;/p&gt;

&lt;p&gt;If a wallet unintentionally relies on a weak pseudo-random number generator (PRNG) instead of a properly functioning True Random Number Generator (TRNG) or if a flaw in a function such as rng_get() causes entropy to be generated incorrectly is the resulting private keys are no longer truly random. Instead of searching an effectively infinite key space, an attacker can narrow the possibilities to a predictable subset and perform an offline search until the correct key is found.&lt;/p&gt;

&lt;p&gt;In cryptography, this is a catastrophic failure. No amount of polished user experience or hardware security can compensate for weak randomness at the point where private keys are created.&lt;/p&gt;

&lt;p&gt;Public technical reports indicate that the root cause lay within the seed generation pipeline, where the hardware entropy source did not behave as intended and portions of the implementation relied on software-generated pseudo-random values. Several analyses associate this behavior with firmware version 4.0.1 on the Mk3, with similar issues affecting later device families until patched releases became available.&lt;/p&gt;

&lt;p&gt;The consequence is straightforward: a seed phrase that should have been cryptographically unpredictable became mathematically predictable.&lt;/p&gt;

&lt;h2&gt;
  
  
  What exactly went wrong?
&lt;/h2&gt;

&lt;p&gt;From an attacker's perspective, this type of vulnerability represents an ideal scenario.&lt;/p&gt;

&lt;p&gt;There is no need to physically compromise the hardware wallet, bypass the PIN, steal the recovery sheet, or intercept network traffic. Instead, the attacker can perform an offline brute-force attack against a dramatically reduced key space until the correct private key is found. Once recovered, the associated Bitcoin can be transferred without ever interacting with the victim's device.&lt;/p&gt;

&lt;p&gt;This is why a flaw in a wallet's random number generation should never be viewed as "just another software bug." It undermines the very foundation of the wallet's security model.&lt;/p&gt;

&lt;p&gt;Unlike vulnerabilities that require complex exploitation chains, a weakness in entropy affects every cryptographic secret generated during the vulnerable period. Once those secrets become predictable, every security mechanism built on top of them effectively collapses.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to prevent it from happening again
&lt;/h2&gt;

&lt;p&gt;For products that rely on cryptography, security controls around randomness should be treated as a first-class engineering requirement rather than an implementation detail.&lt;/p&gt;

&lt;p&gt;First, the entropy source must be validated independently of the surrounding business logic. Its implementation should be reviewed during both architecture reviews and threat-modeling exercises to ensure that cryptographic assumptions remain valid throughout the system.&lt;/p&gt;

&lt;p&gt;Second, silent fallbacks from a True Random Number Generator (TRNG) to a pseudo-random number generator (PRNG) should never occur without explicit security approval, monitoring, and alerting. If the primary entropy source fails, the system should fail safely rather than silently generating weaker cryptographic material.&lt;/p&gt;

&lt;p&gt;Third, the release process should include dedicated verification of cryptographic invariants, including:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;sufficient entropy during key generation;&lt;/li&gt;
&lt;li&gt;the absence of predictable internal states;&lt;/li&gt;
&lt;li&gt;verified versions of cryptographic dependencies;&lt;/li&gt;
&lt;li&gt;reproducible builds to ensure software integrity.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For hardware wallets and HSM-compatible solutions, independent external security audits should be considered mandatory rather than optional. Responsible disclosure programs and transparent vulnerability reporting can significantly reduce the likelihood that critical flaws remain undiscovered for years before causing widespread financial damage.&lt;/p&gt;

&lt;p&gt;Finally, wallet vendors should provide users with secure mechanisms for adding their own entropy, regenerating wallet seeds when necessary, and safely migrating assets whenever a cryptographic weakness is discovered.&lt;/p&gt;

&lt;h2&gt;
  
  
  Security is not a one-time process, it is an ongoing commitment
&lt;/h2&gt;

&lt;p&gt;At INWAY AG, the company behind IronWallet, we consider independent verification and continuous security reviews a fundamental part of our development process. Our wallet infrastructure undergoes regular security audits conducted by independent third-party cybersecurity companies to identify potential weaknesses before they can become real-world risks.&lt;/p&gt;

&lt;p&gt;In addition to external audits, our Security Council meets on a weekly basis to review potential vulnerabilities, analyze emerging threats, and evaluate security improvements across the product ecosystem. This approach allows us to continuously monitor risks, challenge existing assumptions, and strengthen the security mechanisms protecting our users' assets.&lt;/p&gt;

&lt;p&gt;For a non-custodial wallet, where users maintain full control over their private keys, security cannot rely only on the strength of cryptographic algorithms. It requires a proactive security culture, continuous testing, independent reviews, and a development process where potential vulnerabilities are identified and addressed as early as possible.&lt;/p&gt;

&lt;p&gt;At IronWallet, we believe that transparency and continuous improvement are essential principles for building trust in the cryptocurrency industry.&lt;/p&gt;

&lt;h2&gt;
  
  
  Key takeaways
&lt;/h2&gt;

&lt;p&gt;The Coldcard incident serves as a reminder that cryptographic security depends on far more than strong encryption algorithms. Even when the underlying cryptography remains mathematically sound, a seemingly minor implementation flaw can compromise the entire security model.&lt;/p&gt;

&lt;p&gt;Two lessons stand out.&lt;/p&gt;

&lt;p&gt;First, Secure Software Development Lifecycle (SSDLC) practices are not simply a matter of compliance—they are essential safeguards against real financial losses. Security-critical code must undergo continuous verification throughout the entire development lifecycle, from design and implementation to testing, release, and post-deployment monitoring.&lt;/p&gt;

&lt;p&gt;Second, the quality of random number generation is fundamental to cryptographic security. Weak entropy can transform theoretically unbreakable keys into predictable ones, allowing attackers to recover private keys without exploiting the blockchain or physically accessing a user's wallet.&lt;/p&gt;

&lt;p&gt;In cryptography, randomness is not merely another implementation detail.&lt;/p&gt;

&lt;p&gt;It is the foundation upon which every other security guarantee is built.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: The technical discussion in this article is based on publicly available reports and third-party analyses of the Coldcard firmware vulnerability. At the time of writing, Coinkite has acknowledged the firmware issue and released patched versions, while some details regarding the scope of exploitation and financial losses remain based on independent investigations rather than official confirmation.&lt;/p&gt;

</description>
    </item>
    <item>
      <title>Why Adding Developers Does Not Always Increase Engineering Capacity</title>
      <dc:creator>Nica Furs</dc:creator>
      <pubDate>Fri, 31 Jul 2026 10:57:27 +0000</pubDate>
      <link>https://dev.to/nica_furs/why-adding-developers-does-not-always-increase-engineering-capacity-2ipl</link>
      <guid>https://dev.to/nica_furs/why-adding-developers-does-not-always-increase-engineering-capacity-2ipl</guid>
      <description>&lt;p&gt;Engineering demand often grows faster than the team can absorb it. AI features compete with platform work, security fixes, reliability issues and product commitments for the same people. Recruitment helps only when the delivery model can support a larger team.&lt;/p&gt;

&lt;p&gt;As systems expand, work spreads across more services, repositories, dependencies and environments. New engineers need time to understand the architecture and require input from experienced team members before they can contribute independently. Poor ownership, slow reviews and weak documentation can absorb much of the added headcount.&lt;/p&gt;

&lt;p&gt;The practical goal is to increase engineering capacity, not simply payroll. That means shipping valuable work at a steady pace while protecting code quality, system reliability and maintainability. Where local hiring is too slow or the required expertise is narrow, companies can &lt;a href="https://ncube.com/remote-teams" rel="noopener noreferrer"&gt;hire remote developers&lt;/a&gt; to take ownership of a defined technical scope.&lt;/p&gt;

&lt;h2&gt;
  
  
  Headcount Is an Input, Not the Outcome
&lt;/h2&gt;

&lt;p&gt;Two teams with the same number of engineers can produce very different results. One may deploy several times a week with few incidents. Another may spend most of its time resolving dependencies, waiting for approvals and recovering from releases.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Measure            Headcount                 Engineering capacity&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Primary focus   Number of engineers       Useful, reliable technical output&lt;/p&gt;

&lt;p&gt;Common metrics  Team size and open roles  Lead time, deployment frequency&lt;br&gt;
                                                and reliability&lt;br&gt;
Main constraint Hiring speed and payroll  Dependencies, technical debt and&lt;br&gt;
                                                    coordination&lt;/p&gt;

&lt;p&gt;Headcount still matters. A team needs enough people to maintain systems and deliver planned work. The problem starts when leaders treat every delivery issue as a staffing issue.&lt;/p&gt;

&lt;h2&gt;
  
  
  Check the Delivery System Before Opening More Roles
&lt;/h2&gt;

&lt;p&gt;When delivery slows, the constraint may be elsewhere:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;unclear ownership of services;&lt;/li&gt;
&lt;li&gt;too much work in progress;&lt;/li&gt;
&lt;li&gt;long code-review queues;&lt;/li&gt;
&lt;li&gt;manual testing and deployment;&lt;/li&gt;
&lt;li&gt;poor documentation and slow onboarding;&lt;/li&gt;
&lt;li&gt;technical debt that makes small changes risky;&lt;/li&gt;
&lt;li&gt;dependencies that require several teams to coordinate.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Every new team member needs context, access, reviews and decisions from people who are already busy. The result may be more activity without a meaningful improvement in lead time.&lt;/p&gt;

&lt;p&gt;Before hiring, trace how a change moves from idea to production. Where does it wait? Which approvals are repeated? Which systems can only be changed by one or two people? These questions usually reveal the real capacity limits.&lt;/p&gt;

&lt;h2&gt;
  
  
  Team Design Determines How Much Capacity You Keep
&lt;/h2&gt;

&lt;p&gt;High-performing teams reduce the coordination required for routine work. That starts with clear ownership. A team responsible for a defined product area or service can make decisions faster than a group that depends on several departments for every change.&lt;/p&gt;

&lt;p&gt;Automation removes work from the release cycle that does not require engineering judgement. Builds, tests, provisioning and deployment checks can run through the delivery pipeline, while production monitoring helps teams trace failures faster.&lt;/p&gt;

&lt;p&gt;Documentation covers another common bottleneck. When service boundaries, operational procedures and system dependencies are recorded properly, new engineers need less day-to-day guidance from senior staff.&lt;/p&gt;

&lt;p&gt;Capacity also depends on architecture. A tightly coupled system forces teams to coordinate even for small changes. Clear interfaces and service boundaries allow work to proceed more independently.&lt;/p&gt;

&lt;p&gt;Useful capacity metrics include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;lead time for changes;&lt;/li&gt;
&lt;li&gt;deployment frequency;&lt;/li&gt;
&lt;li&gt;change failure rate;&lt;/li&gt;
&lt;li&gt;mean time to recovery;&lt;/li&gt;
&lt;li&gt;escaped defects;&lt;/li&gt;
&lt;li&gt;service reliability.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;DORA’s software delivery performance metrics similarly focus on delivery speed, deployment frequency, change failures, recovery and rework.&lt;/p&gt;

&lt;p&gt;These measures show whether the delivery system is becoming faster and safer or simply busier.&lt;/p&gt;

&lt;h2&gt;
  
  
  Flexible Scaling Works When the Operating Model Is Ready
&lt;/h2&gt;

&lt;p&gt;Permanent hiring is not always fast enough for a product launch, migration, security project or AI initiative. Remote engineers can add specialist knowledge and delivery capacity without requiring every capability to be built internally.&lt;/p&gt;

&lt;p&gt;The model works best when external engineers join the same operating system as the internal team. They should use the same repositories, planning process, coding standards, security controls, documentation practices and definition of done.&lt;/p&gt;

&lt;p&gt;Flexible scaling is less effective when responsibilities are vague. Adding people to an unowned backlog or unstable architecture usually creates more coordination work. A clear workstream, accountable technical owner and measurable outcome make the arrangement easier to manage.&lt;/p&gt;

&lt;p&gt;A distributed talent model can fill capability gaps that are difficult to cover through local recruitment. Cloud engineers, data specialists, DevOps practitioners, cybersecurity experts and legacy modernisation teams can be added around a specific technical requirement. The goal is to remove a delivery constraint, not to increase project staffing without a clear scope.&lt;/p&gt;

&lt;h2&gt;
  
  
  Sustainable Capacity Comes From Better Engineering Systems
&lt;/h2&gt;

&lt;p&gt;Before approving another hiring round, review the delivery environment. If releases are delayed by manual approvals, weak tests, unstable infrastructure or cross-team dependencies, those constraints should be addressed alongside recruitment.&lt;/p&gt;

&lt;p&gt;A practical capacity plan usually combines several actions:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Remove the largest workflow bottleneck.&lt;/li&gt;
&lt;li&gt;Clarify ownership and decision rights.&lt;/li&gt;
&lt;li&gt;Automate repetitive testing and deployment work.&lt;/li&gt;
&lt;li&gt;Reduce risky technical debt in frequently changed areas.&lt;/li&gt;
&lt;li&gt;Add engineers where a genuine skills or workload gap remains.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Engineering capacity should support consistent delivery while keeping production stable, systems secure and the codebase maintainable.&lt;/p&gt;

&lt;p&gt;Hiring helps when roles, responsibilities and delivery processes are already clear. Strong platform foundations, effective tooling and defined ownership allow teams to scale without slowing decisions or increasing dependencies between engineers.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Microsoft’s platform engineering work also highlights the role of standardised development paths in reducing operational toil and simplifying software delivery at scale.&lt;/p&gt;

</description>
      <category>developers</category>
      <category>engineeringcapacity</category>
      <category>development</category>
    </item>
    <item>
      <title>How to Connect Your AI Agent to Live VC Fund Data Using MCP</title>
      <dc:creator>Nica Furs</dc:creator>
      <pubDate>Fri, 24 Jul 2026 14:53:00 +0000</pubDate>
      <link>https://dev.to/nica_furs/how-to-connect-your-ai-agent-to-live-vc-fund-data-using-mcp-3g3j</link>
      <guid>https://dev.to/nica_furs/how-to-connect-your-ai-agent-to-live-vc-fund-data-using-mcp-3g3j</guid>
      <description>&lt;p&gt;If you're building AI workflows for startup founders, fundraising research, or investor intelligence, Fund Momentum now provides an MCP server with 970+ active VC funds, live GP signals, and AI-powered startup matching.&lt;/p&gt;

&lt;p&gt;Here's how to integrate it in 5 minutes.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 1 — Get your API key
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-X&lt;/span&gt; POST https://fundmomentum.vc/_api/agent/register &lt;span class="se"&gt;\&lt;/span&gt;

&amp;nbsp; &lt;span class="nt"&gt;-H&lt;/span&gt; &lt;span class="s2"&gt;"Content-Type: application/json"&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;

&amp;nbsp; &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="s1"&gt;'{"agent_name": "my-agent", "email": "you@company.com"}'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Returns:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="err"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"api_key"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"abc123..."&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="err"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"agent_credits"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="err"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"mcp_endpoint"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"https://fundmomentum.vc/_api/mcp"&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Step 2 — Claude Desktop
&lt;/h2&gt;

&lt;p&gt;~/Library/Application Support/Claude/claude_desktop_config.json:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="err"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"mcpServers"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="err"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"fund-momentum"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="err"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"url"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"https://fundmomentum.vc/_api/mcp"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="err"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"headers"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"X-API-Key"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"YOUR_KEY"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="err"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="err"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Now ask Claude: "Which pre-seed funds in Austria are actively deploying right now?"&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 3 — Python / LangChain
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;requests&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;json&lt;/span&gt;


&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;query_fm&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;tool&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;api_key&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;

&lt;span class="err"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt; &lt;span class="n"&gt;r&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;requests&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;post&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;

&lt;span class="err"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;https://fundmomentum.vc/_api/mcp&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;

&lt;span class="err"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt; &lt;span class="n"&gt;headers&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;X-API-Key&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;api_key&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;Content-Type&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;application/json&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;

&lt;span class="err"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt; &lt;span class="n"&gt;json&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;jsonrpc&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;2.0&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;method&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;tools/call&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;

&lt;span class="err"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;params&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;name&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;tool&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;arguments&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;id&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="err"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt; &lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="err"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt; &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;r&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;json&lt;/span&gt;&lt;span class="p"&gt;()[&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;result&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;



&lt;span class="n"&gt;result&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;query_fm&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="s"&gt;match_startup&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;

&lt;span class="err"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;description&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;B2B SaaS for legal teams, pre-seed, raising €2M, DACH&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;

&lt;span class="err"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;stage&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;pre_seed&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;country&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;Austria&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;

&lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="s"&gt;YOUR_KEY&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="n"&gt;matches&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;json&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;loads&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;result&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;content&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;][&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;][&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;text&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Available tools
&lt;/h2&gt;

&lt;p&gt;search_funds (Starter) — Filter 970+ funds by stage/country/industry&lt;/p&gt;

&lt;p&gt;get_fund (Starter) — Full profile, thesis, check size&lt;/p&gt;

&lt;p&gt;get_fund_signals (Agent) — Live GP signals, deployment status&lt;/p&gt;

&lt;p&gt;match_startup (Agent) — AI matching against your description&lt;/p&gt;

&lt;p&gt;get_gp_profile (Agent) — Individual partner intelligence&lt;/p&gt;

&lt;h2&gt;
  
  
  Every response includes credit balance
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="err"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"_meta"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="err"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"credits_remaining"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;9847&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="err"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"cost_per_call"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"€0.01"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="err"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"billing"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"per_call"&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="err"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Pricing: €10 for 1K credits, €80 for 10K, €500 for 100K. Credits never expire.&lt;/p&gt;

&lt;p&gt;GitHub: schneidavie/fundmomentum&lt;/p&gt;

&lt;p&gt;Register: &lt;a href="https://fundmomentum.vc/for-agents" rel="noopener noreferrer"&gt;https://fundmomentum.vc/for-agents&lt;/a&gt;&lt;/p&gt;

</description>
    </item>
    <item>
      <title>6 Outbound Prospecting Tools That Replace Guesswork With Data in 2026</title>
      <dc:creator>Nica Furs</dc:creator>
      <pubDate>Wed, 22 Jul 2026 14:52:07 +0000</pubDate>
      <link>https://dev.to/nica_furs/6-outbound-prospecting-tools-that-replace-guesswork-with-data-in-2026-2i4m</link>
      <guid>https://dev.to/nica_furs/6-outbound-prospecting-tools-that-replace-guesswork-with-data-in-2026-2i4m</guid>
      <description>&lt;h2&gt;
  
  
  What Separates a Real Outbound Tool From a Glorified Spreadsheet
&lt;/h2&gt;

&lt;p&gt;An outbound prospecting tool needs to do three things in sequence: identify who to contact, confirm you can actually reach them, and help you reach them systematically rather than one email at a time. Miss any one of the three, and you are back to manual work with extra steps.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Apollo.io&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Apollo bundles a 275 million contact database with sequencing, intent data, and CRM sync, aiming to be the single tool an outbound team lives inside all day.&lt;/p&gt;

&lt;p&gt;The Verdict:&amp;nbsp;The sequencing depth is real and the intent layer adds genuine prioritization value. The catch is a reported 15 to 25 percent bounce rate on "verified" contacts, which means the outbound motion built on top of that data inherits some risk before it even starts.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;SignalHire&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;SignalHire covers discovery and verification tightly, returning real-time verified emails and phone numbers from a single search across LinkedIn, GitHub, and company websites.&lt;/p&gt;

&lt;p&gt;The Verdict:&amp;nbsp;Strong on the "who" and the "can I reach them" questions.&amp;nbsp;&lt;a href="https://www.signalhire.com" rel="noopener noreferrer"&gt;SignalHire.com&lt;/a&gt;&amp;nbsp;does not include native sequencing, so most outbound teams pair it with a separate cadence tool, but the accuracy of what it hands off is genuinely high.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Cognism&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Cognism's outbound data is built around manually verified mobile numbers across 15 European markets, checked against country-specific Do Not Call lists, with SOC 2 Type II and ISO 27001 certification behind it.&lt;/p&gt;

&lt;p&gt;The Verdict:&amp;nbsp;For outbound teams targeting the UK and EU specifically, this is close to the compliance and accuracy gold standard. For teams focused purely on North America, the specialization is wasted spend.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Seamless.AI&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Seamless.AI leans into real-time web search rather than a static database, aiming to sidestep the staleness problem that eventually catches up with every large contact database.&lt;/p&gt;

&lt;p&gt;The Verdict:&amp;nbsp;Search volume and speed are genuine strengths. Accuracy consistency is the trade-off, with user reviews reporting a noticeable range between excellent and unusable results depending on the target contact's online footprint.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;LeadIQ&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;LeadIQ captures verified contacts directly from LinkedIn and routes them straight into Salesloft, Outreach, or Salesforce, positioning itself as the connective layer rather than a standalone outbound engine.&lt;/p&gt;

&lt;p&gt;The Verdict:&amp;nbsp;For teams already committed to one of those three sequencing platforms, LeadIQ removes friction elegantly. Outside that specific stack, its standalone value is more limited.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;VoilaNorbert&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;VoilaNorbert combines real-time search with a certainty score on every result and a pricing model that does not charge for a failed search, a small but genuinely outbound-friendly feature.&lt;/p&gt;

&lt;p&gt;The Verdict:&amp;nbsp;Simple, transparent, and low-risk to test. The database, at roughly 100 million prospects, is meaningfully smaller than the enterprise-scale competitors on this list, which limits it for large-volume outbound campaigns.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Comparison Table&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fz0lj26b9ornbhs0lygad.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fz0lj26b9ornbhs0lygad.png" alt=" " width="630" height="436"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  A Practical Way to Test Any Outbound Tool
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Pull your actual current target list, not a sample or demo dataset&lt;/li&gt;
&lt;li&gt;Run discovery and verification through the shortlisted tool&lt;/li&gt;
&lt;li&gt;Send a small, genuinely representative test batch, tracking hard bounces specifically&lt;/li&gt;
&lt;li&gt;Note how much manual work remained after the tool's automation ran its course&lt;/li&gt;
&lt;li&gt;Calculate cost per qualified conversation, not just cost per contact found&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Key Takeaways
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;The strongest outbound tools handle discovery, verification, and sequencing as a connected chain, not isolated steps&lt;/li&gt;
&lt;li&gt;Bundled sequencing convenience sometimes comes at the cost of verification accuracy&lt;/li&gt;
&lt;li&gt;Regional specialization, like Cognism's European focus, can outperform general-purpose global tools for specific markets&lt;/li&gt;
&lt;li&gt;Testing against your actual target list beats trusting any vendor's aggregate accuracy number&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Quick Glossary
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Discovery:&lt;/strong&gt;&amp;nbsp;Locating a contact's likely or confirmed details based on a name, company, or profile.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Verification:&lt;/strong&gt;&amp;nbsp;Confirming a discovered contact detail is currently active and reachable.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Sequencing:&lt;/strong&gt;&amp;nbsp;Automating a multi-touch outreach cadence across email and other channels.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Bounce rate:&lt;/strong&gt;&amp;nbsp;The percentage of sent emails that fail to reach an active inbox, a direct signal of data quality.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Intent data:&lt;/strong&gt;&amp;nbsp;Behavioral signals indicating a contact or company is actively researching or evaluating a solution.&lt;/p&gt;

</description>
    </item>
    <item>
      <title>What developers learn pulling company data from official business registries</title>
      <dc:creator>Nica Furs</dc:creator>
      <pubDate>Tue, 21 Jul 2026 10:45:19 +0000</pubDate>
      <link>https://dev.to/nica_furs/what-developers-learn-pulling-company-data-from-official-business-registries-o47</link>
      <guid>https://dev.to/nica_furs/what-developers-learn-pulling-company-data-from-official-business-registries-o47</guid>
      <description>&lt;p&gt;Open government business registers are a surprisingly useful and surprisingly awkward data source. Here is what teams wish they had known before integrating one.&lt;/p&gt;

&lt;p&gt;Every so often a feature lands on a developer's plate that sounds trivial and turns out to be a rabbit hole. A common one: "let users verify a company by its registration number." How hard could it be? The data is public. There are official registries. Surely it is just an API call.&lt;/p&gt;

&lt;p&gt;It is never just an API call.&lt;/p&gt;

&lt;p&gt;Teams that have wrangled official business-registry data across a few jurisdictions tend to come out the other side with a working feature and a list of things they wish someone had told them first. This is that list. For anyone about to touch company data, open corporate registers, or "know your customer" style verification, it might save a week.&lt;/p&gt;

&lt;h2&gt;
  
  
  Public does not mean easy
&lt;/h2&gt;

&lt;p&gt;The first surprise is that "the data is public" and "the data is accessible" are very different statements.&lt;/p&gt;

&lt;p&gt;Most developed countries maintain an official business register. Legally the core data is public: company name, registration number, legal form, status, directors, sometimes ownership and annual filings. But how a developer actually gets at it ranges from "clean open-data API with a documented schema" to "there is a website, good luck." Some countries publish proper open datasets. Others hide everything behind a form with a session cookie and a CAPTCHA, and their idea of an API is a paginated HTML table.&lt;/p&gt;

&lt;p&gt;So before anyone promises a feature, it is worth spending an afternoon finding out what the source actually offers for the specific countries in scope. The gap between the best and worst national registers is enormous, and it dictates the whole architecture.&lt;/p&gt;

&lt;h2&gt;
  
  
  Identifiers are messier than expected
&lt;/h2&gt;

&lt;p&gt;A company registration number looks like it should be a nice clean primary key. Sometimes it is. Often it is not.&lt;/p&gt;

&lt;p&gt;Formats differ per country, which is expected, but the annoying part is the near-misses. Numbers get formatted with spaces, dots, or country prefixes inconsistently. The same company can appear under a slightly different legal name in two sources. Historical names linger. A company that changed its form keeps its number but changes almost everything else about itself.&lt;/p&gt;

&lt;p&gt;A few habits tend to save pain:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Store the raw identifier exactly as the source gives it, and a normalized version for matching. Never overwrite the original.&lt;/li&gt;
&lt;li&gt;Normalize aggressively for comparison (strip whitespace, punctuation, casing) but display the canonical source value.&lt;/li&gt;
&lt;li&gt;Treat the registration number plus the country as the real key. The number alone is not globally unique.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;code&gt;// naive normalization that catches most matching bugs&lt;br&gt;
function normalizeRegNo(raw) {&lt;br&gt;
  return raw&lt;br&gt;
    .toUpperCase()&lt;br&gt;
    .replace(/[\s.\-\/]/g, "")   // spaces, dots, dashes, slashes&lt;br&gt;
    .replace(/^[A-Z]{2}(?=\d)/, ""); // strip a leading country prefix before digits&lt;br&gt;
}&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;That last line is deliberately conservative. Stripping prefixes is risky, because in some jurisdictions the letters are part of the number, not a country code. Which points to the real lesson.&lt;/p&gt;

&lt;h2&gt;
  
  
  Model the data around "this is a claim from a source at a point in time"
&lt;/h2&gt;

&lt;p&gt;The mistake teams tend to make early is treating registry data as the truth. It is not. It is what a particular source reported at a particular moment. Sources lag. They disagree. They fix errors. A company can be marked active in one place and struck off in another because one updated last week and the other last quarter.&lt;/p&gt;

&lt;p&gt;The moment a schema stops storing &lt;code&gt;company.status = "active"&lt;/code&gt; and &lt;code&gt;starts storing status = "active", source = X, retrieved_at = timestamp&lt;/code&gt;, everything gets easier. Conflicts become visible instead of silently overwriting each other. The system can show a user where a fact came from and how fresh it is, which turns out to be the single most trust-building thing in the whole feature. People believe "active as of yesterday, per the national register" far more than a bare green checkmark.&lt;/p&gt;

&lt;p&gt;This is basically provenance, and for anything verification-flavored, it belongs in the design from day one. Retrofitting provenance onto a schema that assumed single-source truth is miserable.&lt;/p&gt;

&lt;h2&gt;
  
  
  Freshness is a product decision, not just a technical one
&lt;/h2&gt;

&lt;p&gt;Company data changes: new directors, address changes, dissolutions, name changes. How stale is too stale depends entirely on what the data is used for. Displaying a company profile? Daily or weekly is probably fine. Making a decision that carries legal or financial weight? It needs to be current, and the timestamp should be visible.&lt;/p&gt;

&lt;p&gt;The refresh strategy is worth deciding explicitly rather than letting it emerge by accident. Cache hard for read-heavy display, but keep a path to force a fresh pull when it matters. And always surface the "last updated" value to the user. Hiding it does not make the data fresher, it just makes the application silently responsible for its staleness.&lt;/p&gt;

&lt;h2&gt;
  
  
  Rate limits and being a good citizen
&lt;/h2&gt;

&lt;p&gt;Official registers, and the aggregators that sit on top of them, are often run on modest infrastructure or with genuine per-query costs. Hammering them with unbounded requests is both rude and a good way to get blocked.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Batch and cache. Do not re-fetch a company that was looked at an hour ago.&lt;/li&gt;
&lt;li&gt;Respect rate limits, and back off politely on errors instead of retrying in a tight loop.&lt;/li&gt;
&lt;li&gt;For bulk data, look for an actual bulk or open-data download rather than scraping record by record. Many registers offer one, and it is almost always the right answer for analytics.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  When to build versus when to borrow
&lt;/h2&gt;

&lt;p&gt;Here is the honest conclusion. For a single well-served country with a good open-data API, integrating directly is very doable and worth doing. For multi-country coverage, or for jurisdictions with awkward or paywalled registers, the integration and normalization work adds up fast, and it is often cheaper to use an aggregator or a specialist that has already solved the messy parts.&lt;/p&gt;

&lt;p&gt;This is jurisdiction-dependent in a big way. Some countries make it a joy. Estonia, for example, is unusually developer-friendly here: company data, ownership, and filings are openly available and genuinely structured, which is a large part of why so many digital businesses base themselves there. For teams working with entities in a specific country that would rather not build the plumbing themselves, providers who deal with these registers daily, like &lt;a href="https://capture.ee/" rel="noopener noreferrer"&gt;Capture&lt;/a&gt;, handle the formation and verification side and can be a shortcut past a lot of this. Either way, the principles above still apply to whatever the data source returns.&lt;/p&gt;

&lt;h2&gt;
  
  
  The takeaways
&lt;/h2&gt;

&lt;p&gt;The four things worth remembering:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Check what the source actually offers before designing anything. Public does not mean accessible.&lt;/li&gt;
&lt;li&gt;Store raw and normalized identifiers, and key on number plus country.&lt;/li&gt;
&lt;li&gt;Model every fact as a claim with a source and a timestamp. Provenance is the feature.&lt;/li&gt;
&lt;li&gt;Surface freshness to the user, and be a polite API citizen.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Company data looks boring from the outside and turns out to be a neat little case study in provenance, data modeling, and the gap between "public" and "usable." For anyone about to go down this road, hopefully this shortens the trip.&lt;/p&gt;

&lt;p&gt;What official registers have developers found especially good or especially painful to work with? The war stories tend to pile up in the comments.&lt;/p&gt;

</description>
      <category>webdev</category>
      <category>opendata</category>
      <category>api</category>
      <category>datascience</category>
    </item>
    <item>
      <title>A Practical Framework for Building AI Products Operators Actually Adopt</title>
      <dc:creator>Nica Furs</dc:creator>
      <pubDate>Mon, 20 Jul 2026 12:09:08 +0000</pubDate>
      <link>https://dev.to/nica_furs/a-practical-framework-for-building-ai-products-operators-actually-adopt-32ng</link>
      <guid>https://dev.to/nica_furs/a-practical-framework-for-building-ai-products-operators-actually-adopt-32ng</guid>
      <description>&lt;p&gt;Developers are building faster than ever. AI tools, APIs, open-source frameworks, cloud infrastructure, and streamlined deployment now make it possible to create prototypes in days that would have taken months in previous cycles. That speed is valuable. However, in enterprise and service-business environments, a prototype is not the same as adoption.&lt;/p&gt;

&lt;p&gt;Sam Lee’s perspective comes from operating experience rather than engineering alone. As former Chairman and CEO of Prospect Medical Holdings, he saw how technology decisions unfold in complex environments involving many stakeholders. In healthcare, a product must account for compliance, urgency, staffing, patient trust, documentation, and operational accountability. That experience now shapes how he advises and evaluates AI-enabled companies through &lt;a href="https://samleeventures.com/" rel="noopener noreferrer"&gt;Sam Lee Ventures&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;For developers building AI products, the key lesson is simple: the user is not merely a persona. The user is part of a workflow with constraints, incentives, exceptions, escalation points, and potential failure modes. If a product does not account for these realities, implementation may stall regardless of how impressive its model or interface appears.&lt;/p&gt;

&lt;p&gt;A practical framework begins with the job to be done. What specific work is the AI product improving? Is it routing information, answering questions, summarizing records, prioritizing tasks, qualifying leads, drafting communications, detecting anomalies, or coordinating follow-up? The more specific the workflow, the easier it becomes to design around measurable value.&lt;/p&gt;

&lt;p&gt;The second step is mapping the handoff. AI products often fail not because the model is weak, but because the product does not define what happens next. Who receives the output? Can the user edit it? When does a human review it? What confidence threshold triggers escalation? How is the action logged? What should the system do when it does not know?&lt;/p&gt;

&lt;p&gt;The third step is respecting data quality. Operators understand that business data is rarely perfect. Names may be inconsistent, records incomplete, fields outdated, and important context stored outside the system of record. Developers who build around idealized datasets may be surprised when production use exposes edge cases. A strong product should communicate uncertainty honestly and remain useful even when the data is messy.&lt;/p&gt;

&lt;p&gt;The fourth step is measuring adoption, not merely usage. A team may log in because leadership requested it, but that does not necessarily mean the product is creating value. Better measures include time saved, faster response times, reduced revenue leakage, fewer manual steps, faster onboarding, clearer accountability, and fewer missed handoffs.&lt;/p&gt;

&lt;p&gt;The fifth step is designing for both the buyer and the user. In many service businesses, the executive buyer wants productivity, consistency, visibility, and return on investment. The day-to-day user wants fewer interruptions, less duplicate work, and a tool that does not make the job more difficult. Products that serve both audiences have a stronger chance of achieving durable adoption.&lt;/p&gt;

&lt;p&gt;This is why domain context matters. Builders do not need to become hospital executives, bankers, attorneys, or operators in every vertical. However, they need enough curiosity to understand the operating environment before presenting a solution. The strongest technical teams spend time studying the workflow, not only the codebase.&lt;/p&gt;

&lt;p&gt;Lee’s work at Sam Lee Ventures focuses on this connection between technology and execution. The most promising AI companies will not be those that demonstrate model capability alone. They will be the companies that translate that capability into outcomes operators can trust, manage, and measure.&lt;/p&gt;

&lt;p&gt;The opportunity for developers is significant. AI products that understand operational realities can become part of the infrastructure of modern businesses. However, adoption will favor products that are practical, explainable, integrated, secure, and measurable. In applied AI, the challenge is no longer simply building something that works. It is building something organizations can actually use.&lt;/p&gt;

</description>
    </item>
    <item>
      <title>How developers can think about payment infrastructure beyond the checkout button</title>
      <dc:creator>Nica Furs</dc:creator>
      <pubDate>Fri, 17 Jul 2026 08:32:31 +0000</pubDate>
      <link>https://dev.to/nica_furs/how-developers-can-think-about-payment-infrastructure-beyond-the-checkout-button-5217</link>
      <guid>https://dev.to/nica_furs/how-developers-can-think-about-payment-infrastructure-beyond-the-checkout-button-5217</guid>
      <description>&lt;p&gt;For most users, a payment is simple. They choose a product, click a button, approve the payment, and expect everything to work.&lt;/p&gt;

&lt;p&gt;For developers, that button is only the front door.&lt;/p&gt;

&lt;p&gt;Behind it sits a chain of decisions, events, checks, fallbacks, messages, statuses, and financial movements. A checkout can look clean on the surface while the infrastructure behind it is quietly carrying the real weight: authorisation, authentication, payment method availability, retries, settlement, reconciliation, refunds, chargebacks, reporting, and fraud prevention.&lt;/p&gt;

&lt;p&gt;That is why payment infrastructure should not be treated as a final integration task at the end of a product roadmap. It is part of the product experience itself.&lt;/p&gt;

&lt;p&gt;If the payment layer is slow, fragile, or badly designed, users do not blame the payment provider. They blame the business.&lt;/p&gt;

&lt;h2&gt;
  
  
  The checkout button is only the visible layer
&lt;/h2&gt;

&lt;p&gt;A good payment experience often feels invisible. The customer should not need to understand what happens after they click “Pay”. But developers do.&lt;/p&gt;

&lt;p&gt;A simplified payment flow might look like this:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;The customer selects a payment method.&lt;/li&gt;
&lt;li&gt;The frontend sends the payment request.&lt;/li&gt;
&lt;li&gt;The backend creates or confirms a payment.&lt;/li&gt;
&lt;li&gt;The customer may need to complete authentication.&lt;/li&gt;
&lt;li&gt;The payment is authorised, declined, or placed in a pending state.&lt;/li&gt;
&lt;li&gt;The system receives status updates.&lt;/li&gt;
&lt;li&gt;The order, subscription, wallet, or account balance is updated.&lt;/li&gt;
&lt;li&gt;The transaction is settled and later reconciled.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Each step can fail in different ways.&lt;/p&gt;

&lt;p&gt;A card may be declined. A customer may abandon authentication. A webhook may arrive late. A bank may return a pending status. A payment method may not be available in a particular market. A refund may need to be tracked separately from the original transaction.&lt;/p&gt;

&lt;p&gt;From a user’s point of view, these are all “payment issues”. From an engineering point of view, they are state-management problems.&lt;/p&gt;

&lt;h2&gt;
  
  
  Payment status is not always binary
&lt;/h2&gt;

&lt;p&gt;One common mistake is treating payments as either successful or failed.&lt;/p&gt;

&lt;p&gt;In reality, payment states can be more nuanced. A transaction can be:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Created&lt;/li&gt;
&lt;li&gt;Pending&lt;/li&gt;
&lt;li&gt;Requires customer action&lt;/li&gt;
&lt;li&gt;Authorised&lt;/li&gt;
&lt;li&gt;Captured&lt;/li&gt;
&lt;li&gt;Failed&lt;/li&gt;
&lt;li&gt;Cancelled&lt;/li&gt;
&lt;li&gt;Refunded&lt;/li&gt;
&lt;li&gt;Partially refunded&lt;/li&gt;
&lt;li&gt;Disputed&lt;/li&gt;
&lt;li&gt;Settled&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For developers, this means the payment state should not be buried as a simple boolean like&amp;nbsp;&lt;code&gt;isPaid&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;That may work for a very basic flow, but it becomes limiting as soon as the business adds subscriptions, partial captures, delayed fulfilment, manual reviews, refunds, chargebacks, or multiple payment methods.&lt;/p&gt;

&lt;p&gt;A better model treats payments as lifecycle events. The order or account state should respond to payment events rather than assume that the first response from the payment API is the final truth.&lt;/p&gt;

&lt;p&gt;A useful rule of thumb: your frontend can guide the payment experience, but your backend should own the final state.&lt;/p&gt;

&lt;h2&gt;
  
  
  Webhooks are not optional plumbing
&lt;/h2&gt;

&lt;p&gt;Webhooks are often treated as a technical detail, but they are central to reliable payment infrastructure.&lt;/p&gt;

&lt;p&gt;The first API response tells you what happened at that moment. A webhook tells your system what happened later.&lt;/p&gt;

&lt;p&gt;This matters because payments are asynchronous by nature. A customer may complete authentication after being redirected. A bank may update the transaction status. A dispute may be opened days later. A refund may succeed after the original request has already returned a pending response.&lt;/p&gt;

&lt;p&gt;A resilient webhook setup should account for:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Duplicate events&lt;/li&gt;
&lt;li&gt;Out-of-order delivery&lt;/li&gt;
&lt;li&gt;Delayed delivery&lt;/li&gt;
&lt;li&gt;Failed delivery attempts&lt;/li&gt;
&lt;li&gt;Signature verification&lt;/li&gt;
&lt;li&gt;Idempotent processing&lt;/li&gt;
&lt;li&gt;Internal retry logic&lt;/li&gt;
&lt;li&gt;Event logging for audits and debugging&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Idempotency is especially important. If the same webhook arrives twice, the system should not create two orders, send two invoices, or give the customer double access.&lt;/p&gt;

&lt;p&gt;Think of webhooks like delivery drivers in a busy city. Most arrive on time, but some take a different route, some arrive late, and occasionally two drivers bring the same parcel. Your receiving process needs to handle that without causing chaos.&lt;/p&gt;

&lt;h2&gt;
  
  
  Failed payments are often infrastructure problems
&lt;/h2&gt;

&lt;p&gt;Not every failed payment is caused by a customer having insufficient funds.&lt;/p&gt;

&lt;p&gt;Payments can fail because of:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Poor authentication handling&lt;/li&gt;
&lt;li&gt;Missing local payment methods&lt;/li&gt;
&lt;li&gt;Incomplete billing details&lt;/li&gt;
&lt;li&gt;Network or timeout issues&lt;/li&gt;
&lt;li&gt;Weak retry logic&lt;/li&gt;
&lt;li&gt;Poor routing decisions&lt;/li&gt;
&lt;li&gt;Unsupported currencies&lt;/li&gt;
&lt;li&gt;Fraud rules that are too strict&lt;/li&gt;
&lt;li&gt;Confusing checkout UX&lt;/li&gt;
&lt;li&gt;Payment methods that do not match customer preferences&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For SaaS and ecommerce businesses, failed payments are not just technical events. They affect revenue, conversion, churn, customer support, and trust.&lt;/p&gt;

&lt;p&gt;A developer-friendly payment setup should make it easy to understand why a payment failed and what should happen next.&lt;/p&gt;

&lt;p&gt;For example:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Should the customer be asked to try another card?&lt;/li&gt;
&lt;li&gt;Should the system retry automatically?&lt;/li&gt;
&lt;li&gt;Should the subscription enter a grace period?&lt;/li&gt;
&lt;li&gt;Should fulfilment be paused?&lt;/li&gt;
&lt;li&gt;Should support be notified?&lt;/li&gt;
&lt;li&gt;Should the event be shown in the admin dashboard?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The payment provider’s API response is only one part of the answer. The product logic around that response is where the customer experience is shaped.&lt;/p&gt;

&lt;h2&gt;
  
  
  Multi-market businesses need local payment thinking
&lt;/h2&gt;

&lt;p&gt;Payment infrastructure becomes more complex when a business expands across markets.&lt;/p&gt;

&lt;p&gt;A checkout that works well in one country may underperform in another. Customers in different regions prefer different ways to pay. Some markets are card-heavy. Others rely more on bank transfers, wallets, local payment methods, or alternative payment methods.&lt;/p&gt;

&lt;p&gt;For developers, this creates several product and infrastructure questions:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Which payment methods should appear for each country?&lt;/li&gt;
&lt;li&gt;Which currencies should be supported?&lt;/li&gt;
&lt;li&gt;Should payment options be shown dynamically?&lt;/li&gt;
&lt;li&gt;How should failed payment attempts be routed?&lt;/li&gt;
&lt;li&gt;How should refunds work across payment methods?&lt;/li&gt;
&lt;li&gt;How should reconciliation happen across accounts, currencies, and processors?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Hard-coding one global payment flow can become expensive later. A more flexible setup allows payment methods, currencies, and routing logic to adapt as the business grows.&lt;/p&gt;

&lt;p&gt;This is where working with a provider such as&amp;nbsp;&lt;a href="https://payabl.com/" rel="noopener noreferrer"&gt;payabl&lt;/a&gt;.’s payment infrastructure for digital businesses&amp;nbsp;can help teams connect online payments, in-person payments, business accounts, cards, and local payment methods within a broader operational setup.&lt;/p&gt;

&lt;p&gt;The payment layer should talk to the rest of the business&lt;/p&gt;

&lt;p&gt;Payments do not live in isolation.&lt;/p&gt;

&lt;p&gt;A single transaction may touch:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Checkout&lt;/li&gt;
&lt;li&gt;Order management&lt;/li&gt;
&lt;li&gt;Subscription billing&lt;/li&gt;
&lt;li&gt;CRM&lt;/li&gt;
&lt;li&gt;Accounting&lt;/li&gt;
&lt;li&gt;Fraud monitoring&lt;/li&gt;
&lt;li&gt;Customer support&lt;/li&gt;
&lt;li&gt;Business intelligence&lt;/li&gt;
&lt;li&gt;Reconciliation&lt;/li&gt;
&lt;li&gt;Payout reporting&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If payment data is difficult to access or interpret, every team downstream feels it.&lt;/p&gt;

&lt;p&gt;Developers can reduce this pain by designing payment infrastructure with internal users in mind. That means storing useful references, making transaction states visible, logging important events, and ensuring finance teams can reconcile what happened.&lt;/p&gt;

&lt;p&gt;For example, a transaction record should ideally connect the technical payment event with business context:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Customer ID&lt;/li&gt;
&lt;li&gt;Order ID&lt;/li&gt;
&lt;li&gt;Payment ID&lt;/li&gt;
&lt;li&gt;Payment method&lt;/li&gt;
&lt;li&gt;Currency&lt;/li&gt;
&lt;li&gt;Amount&lt;/li&gt;
&lt;li&gt;Status&lt;/li&gt;
&lt;li&gt;Failure reason&lt;/li&gt;
&lt;li&gt;Refund status&lt;/li&gt;
&lt;li&gt;Settlement reference&lt;/li&gt;
&lt;li&gt;Timestamp history&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This makes debugging easier, but it also makes reporting and financial operations more reliable.&lt;/p&gt;

&lt;h2&gt;
  
  
  Card issuing and wallets add another layer
&lt;/h2&gt;

&lt;p&gt;For some businesses, payment infrastructure does not stop at accepting payments.&lt;/p&gt;

&lt;p&gt;They may also need business accounts, virtual cards, physical cards, Apple Pay provisioning, spend controls, or operational payment flows for teams and suppliers.&lt;/p&gt;

&lt;p&gt;That creates another technical layer. Instead of only thinking about money coming in, developers also need to think about how money moves out, how cards are created, how cards are tokenised, how wallet provisioning works, and how spend is monitored.&lt;/p&gt;

&lt;p&gt;Virtual cards, for example, can support use cases such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Team spending&lt;/li&gt;
&lt;li&gt;Supplier payments&lt;/li&gt;
&lt;li&gt;Marketing budgets&lt;/li&gt;
&lt;li&gt;Travel expenses&lt;/li&gt;
&lt;li&gt;Platform operations&lt;/li&gt;
&lt;li&gt;Controlled recurring payments&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;When cards are provisioned into wallets such as Apple Pay, the user experience becomes even more immediate. But the infrastructure still needs to handle eligibility, tokenisation, card status, authentication, controls, and transaction monitoring.&lt;/p&gt;

&lt;p&gt;Again, the simple user experience depends on a lot of careful backend design.&lt;/p&gt;

&lt;h2&gt;
  
  
  What developers should look for in payment infrastructure
&lt;/h2&gt;

&lt;p&gt;When evaluating a payment setup, developers should look beyond whether the API can create a transaction.&lt;/p&gt;

&lt;p&gt;Useful questions include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Is the API well documented?&lt;/li&gt;
&lt;li&gt;Are payment states clear and predictable?&lt;/li&gt;
&lt;li&gt;Are webhooks reliable and easy to test?&lt;/li&gt;
&lt;li&gt;Is idempotency supported?&lt;/li&gt;
&lt;li&gt;Can the system support multiple payment methods?&lt;/li&gt;
&lt;li&gt;Can it support multiple markets and currencies?&lt;/li&gt;
&lt;li&gt;How are refunds, disputes, and chargebacks handled?&lt;/li&gt;
&lt;li&gt;Is reporting detailed enough for finance teams?&lt;/li&gt;
&lt;li&gt;Are there tools for testing edge cases?&lt;/li&gt;
&lt;li&gt;Can the infrastructure support future products, such as cards or in-person payments?&lt;/li&gt;
&lt;li&gt;Does the provider help reduce operational complexity as the business scales?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The best payment infrastructure is not only about accepting a payment today. It is about supporting the product, finance, risk, and customer experience needs that appear tomorrow.&lt;/p&gt;

&lt;h2&gt;
  
  
  Build payments like a product system, not a checkout add-on
&lt;/h2&gt;

&lt;p&gt;A checkout button may look like one small part of the user journey, but it connects to some of the most important parts of a business.&lt;/p&gt;

&lt;p&gt;Revenue, trust, fulfilment, reporting, cash flow, and customer retention all pass through the payment layer.&lt;/p&gt;

&lt;p&gt;For developers, that means payment infrastructure deserves the same level of design thinking as authentication, database architecture, observability, or security.&lt;/p&gt;

&lt;p&gt;A good payment system should be reliable when things go right, but also predictable when things go wrong. It should help teams understand payment states, recover from failures, support new markets, and give finance teams the data they need.&lt;/p&gt;

&lt;p&gt;Because in the end, a payment is not just a button.&lt;/p&gt;

&lt;p&gt;It is a business-critical workflow hiding behind one.&lt;/p&gt;

</description>
      <category>paymentinfrastructure</category>
      <category>api</category>
      <category>fintech</category>
      <category>softwaredevelopment</category>
    </item>
    <item>
      <title>Best IPTV UK 2026: The 7 Best IPTV UK Providers Tested and Ranked</title>
      <dc:creator>Nica Furs</dc:creator>
      <pubDate>Mon, 06 Jul 2026 15:38:59 +0000</pubDate>
      <link>https://dev.to/nica_furs/best-iptv-uk-2026-the-7-best-iptv-uk-providers-tested-and-ranked-4d8a</link>
      <guid>https://dev.to/nica_furs/best-iptv-uk-2026-the-7-best-iptv-uk-providers-tested-and-ranked-4d8a</guid>
      <description>&lt;p&gt;Choosing the best IPTV UK service in 2026 is not easy. The market is full of IPTV UK providers that all claim to offer thousands of channels, real 4K and a cheap IPTV subscription, but only a handful deliver. To help you pick the best IPTV UK service with confidence, we spent weeks testing the leading IPTV providers on real devices at peak times. Here are the 7 best IPTV UK services, ranked, with exact prices and honest verdicts.&lt;/p&gt;

&lt;h2&gt;
  
  
  How We Ranked the Best IPTV UK Services
&lt;/h2&gt;

&lt;p&gt;We did not just search for the best IPTV UK service and copy a list. We subscribed to each IPTV service and used it for at least five days, running every one during peak evening hours when server load is highest. We tested live sport, checked whether the 4K was genuine or upscaled, and measured how fast each IPTV provider replied to support. Only the seven IPTV subscriptions below passed every test, and each is the best IPTV UK option for a different type of viewer.&lt;/p&gt;

&lt;h2&gt;
  
  
  The 7 Best IPTV UK Services 2026
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;1. &lt;a href="https://dev.tourl"&gt;NUXARATV.COM&lt;/a&gt;: Best IPTV UK Overall&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;NUXARATV is the best IPTV UK service overall in 2026. With more than 55,000 live channels, it offers the largest channel catalogue of any IPTV UK provider in this comparison, plus 150,000 movies and shows in 4K, HD and SD. Anti-freeze technology keeps streams stable, all sport channels are included, and you can choose 1, 2 or 3 connections. The best IPTV UK pick for anyone who wants the widest choice.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;NUXARATV features:&lt;/strong&gt;&lt;br&gt;
✔ 55,000+ live channels&lt;br&gt;
✔ 150,000+ movies &amp;amp; shows&lt;br&gt;
✔ 4K / HD / SD quality&lt;br&gt;
✔ All UK sport channels included&lt;br&gt;
✔ Anti-freeze technology&lt;br&gt;
✔ 1, 2 or 3 connections&lt;br&gt;
✔ Works on any Firestick&lt;br&gt;
✔ Price: £56 / year&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. KEZELTV.COM:&amp;nbsp; Best IPTV UK for Sport&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;KEZELTV is the best IPTV subscription for sport and on-demand content in the UK. This IPTV UK provider offers more than 30,000 channels and 190,000 movies and shows, all UK sport channels and pay-per-view included, in 4K, FHD and HD. A built-in VPN, anti-freeze, 4-day catch-up TV and EPG complete the package, with a 30-day money-back guarantee that makes it one of the lowest-risk IPTV subscriptions to try.&lt;/p&gt;

&lt;p&gt;KEZELTV features:&lt;br&gt;
✔ 30,000+ live channels&lt;br&gt;
✔ 190,000+ movies &amp;amp; shows&lt;br&gt;
✔ 4K / FHD / HD quality&lt;br&gt;
✔ All UK sport channels + PPV&lt;br&gt;
✔ Anti-freeze &amp;amp; built-in VPN&lt;br&gt;
✔ Catch-up TV 4 days + EPG&lt;br&gt;
✔ 30-day money-back guarantee&lt;br&gt;
✔ Price: £60 / year (+1 month free)&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. OREXETV.COM:&amp;nbsp; Most Trusted IPTV UK Provider&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;OREXETV is the most trusted IPTV UK provider, rated 4.8 out of 5 on Trustpilot, the highest score in this comparison. This best IPTV UK service includes more than 25,000 channels and 130,000 movies and shows in genuine 4K, with anti-freeze, a built-in VPN, catch-up TV and pay-per-view. Stability during live sport is the best we tested. For anyone who wants a reliable IPTV subscription above all, OREXETV is a safe bet.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;OREXETV features:&lt;/strong&gt;&lt;br&gt;
✔ 25,000+ live channels&lt;br&gt;
✔ 130,000+ movies &amp;amp; shows&lt;br&gt;
✔ Trustpilot 4.8/5 (best rated)&lt;br&gt;
✔ Genuine 4K / FHD / SD&lt;br&gt;
✔ Anti-freeze &amp;amp; built-in VPN&lt;br&gt;
✔ Catch-up TV + pay-per-view&lt;br&gt;
✔ Best sport stability&lt;br&gt;
✔ Price: £62 / year&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;4. TVOXAR.COM:&amp;nbsp; Best IPTV UK Subscription for Content&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;TVOXAR is the best IPTV UK provider for maximum content. This IPTV subscription offers more than 30,000 channels and 150,000 movies and shows, including over 2,000 dedicated sport channels in 4K. A built-in VPN, anti-freeze, catch-up TV and EPG are all included, and the annual plan gives one month free. Ideal for UK sport fans and lovers of international content.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;TVOXAR features:&lt;/strong&gt;&lt;br&gt;
✔ 30,000+ live channels&lt;br&gt;
✔ 150,000+ movies &amp;amp; shows&lt;br&gt;
✔ 2,000+ sport channels in 4K&lt;br&gt;
✔ 4K / HD / SD quality&lt;br&gt;
✔ Anti-freeze &amp;amp; built-in VPN&lt;br&gt;
✔ Catch-up TV + EPG&lt;br&gt;
✔ 1 month free (annual plan)&lt;br&gt;
✔ Price: £63 / year&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;5. NEXOMIR.COM: Best Value IPTV UK Subscription&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;NEXOMIR offers the best value of the IPTV UK providers we tested. This IPTV subscription combines more than 30,000 channels and 150,000 movies and shows in 4K, at one of the lowest prices. Anti-freeze held firm through every test, and support replied in under ten minutes. A cheap IPTV subscription with no compromise on the catalogue.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;NEXOMIR features:&lt;/strong&gt;&lt;br&gt;
✔ 30,000+ live channels&lt;br&gt;
✔ 150,000+ movies &amp;amp; shows&lt;br&gt;
✔ Genuine 4K / FHD / SD&lt;br&gt;
✔ Best value annual plan&lt;br&gt;
✔ Anti-freeze &amp;amp; built-in VPN&lt;br&gt;
✔ Support under 10 minutes&lt;br&gt;
✔ Fast channel switching&lt;br&gt;
✔ Price: £55 / year&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;6. VISSOLOTV.COM Biggest VOD Library&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;VISSOLOTV has the biggest on-demand library of any IPTV UK service in this comparison, with close to 198,000 movies and shows. If you watch more box sets than live TV, this is the IPTV UK provider to choose. This IPTV subscription also includes more than 25,000 channels, anti-freeze, stable servers and a 7-day money-back guarantee. A great choice for households that stream mostly on demand.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;VISSOLOTV features:&lt;/strong&gt;&lt;br&gt;
✔ 25,000+ live channels&lt;br&gt;
✔ 198,000+ movies &amp;amp; shows (biggest VOD)&lt;br&gt;
✔ 4K / FHD / HD / SD quality&lt;br&gt;
✔ Anti-freeze technology&lt;br&gt;
✔ Stable servers&lt;br&gt;
✔ 7-day money-back guarantee&lt;br&gt;
✔ Great for films &amp;amp; box sets&lt;br&gt;
✔ Price: £68 / year&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;7. TVZITAM.COM Cheapest IPTV UK Subscription&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;TVZITAM is the cheapest IPTV subscription and the most flexible in the UK. It is the only IPTV UK provider here to offer a monthly plan, ideal for an extended free IPTV trial. Its annual price is the lowest in this comparison. This IPTV subscription includes more than 15,000 channels, 60,000 movies and shows, 99.9% guaranteed uptime and 24/7 support. Fully M3U and Xtream Codes compatible, it works on any IPTV box or Android TV box.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;TVZITAM features:&lt;/strong&gt;&lt;br&gt;
✔ 15,000+ live channels&lt;br&gt;
✔ 60,000+ movies &amp;amp; shows&lt;br&gt;
✔ Monthly plan available&lt;br&gt;
✔ Cheapest IPTV subscription&lt;br&gt;
✔ 99.9% guaranteed uptime&lt;br&gt;
✔ 24/7 live chat support&lt;br&gt;
✔ M3U &amp;amp; Xtream Codes compatible&lt;br&gt;
✔ Price: £53 / year&lt;/p&gt;

&lt;h2&gt;
  
  
  What Makes the Best IPTV UK Service
&lt;/h2&gt;

&lt;p&gt;Server stability at peak times is the most important factor when choosing the best IPTV UK service. An IPTV UK provider whose streams drop during a live event is not a serious option, whatever the price. Genuine 4K, fast setup, responsive support and a clear guarantee also matter. Always use a free IPTV trial before buying an annual IPTV subscription, ideally in the evening. Be wary of any cheap IPTV subscription under £3 a month, as the best IPTV UK service usually costs £5 to £7 a month on an annual plan.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to Set Up Your IPTV Subscription on a Firestick
&lt;/h2&gt;

&lt;p&gt;After you buy IPTV, you receive your login details by email within minutes. For a Firestick, search for IPTV Smarters Pro or TiviMate in the Amazon app store and install it. On Android TV, use the Google Play Store, and on iPhone or iPad, download GSE Smart IPTV. Enter your details and all your channels load within seconds. For the best experience, use an ethernet connection rather than wifi, especially for 4K and live sport.&lt;/p&gt;

&lt;h2&gt;
  
  
  Is IPTV Legal in the UK?
&lt;/h2&gt;

&lt;p&gt;IPTV technology is completely legal in the UK. The legal status of a service depends on whether the IPTV UK provider holds the correct broadcasting rights. The signs of a serious IPTV subscription are secure payment, transparent terms, a refund policy and responsive support. All seven IPTV providers here offer a free IPTV trial before you buy.&lt;/p&gt;

&lt;h2&gt;
  
  
  Frequently Asked Questions
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Which is the best IPTV UK service in 2026?&lt;/strong&gt;&lt;br&gt;
NUXARATV is the best IPTV UK service overall with 55,000 channels, KEZELTV is the best IPTV subscription for sport, and OREXETV is the most trusted IPTV UK provider (Trustpilot 4.8/5).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What is the cheapest IPTV UK subscription?&lt;/strong&gt;&lt;br&gt;
TVZITAM is the cheapest IPTV subscription at £53 a year, followed by NEXOMIR at £55 and NUXARATV at £56. All offer a free IPTV trial.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How much does an IPTV subscription cost in the UK?&lt;/strong&gt;&lt;br&gt;
A quality IPTV subscription costs between £53 and £68 a year, roughly £4.40 to £5.70 a month.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Does IPTV work on a Firestick?&lt;/strong&gt;&lt;br&gt;
Yes. Every IPTV UK service here works on the Amazon Firestick via apps like IPTV Smarters Pro and TiviMate, the most popular way to watch IPTV in the UK.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How do I get a free IPTV trial?&lt;/strong&gt;&lt;br&gt;
All seven IPTV UK providers here offer a free IPTV trial. Use it in the evening on a live sport stream to judge the best IPTV UK service under peak load.&lt;/p&gt;

&lt;h2&gt;
  
  
  Final Verdict
&lt;/h2&gt;

&lt;p&gt;After our tests, NUXARATV is the best IPTV UK service in 2026 thanks to its 55,000 channels, followed by KEZELTV for sport. OREXETV remains the most trusted IPTV UK provider, while TVZITAM and NEXOMIR offer the cheapest IPTV subscription. Whatever you choose, use a free IPTV trial before you buy IPTV, and pick the IPTV UK provider that best matches your needs.&lt;/p&gt;

</description>
      <category>iptv</category>
    </item>
  </channel>
</rss>
