Ana içeriğe geç
友田 陽大

Free Resources

Practical know-how for your decision

For executives weighing whether to outsource or build in-house, and for developers shipping fast with AI. I publish field-tested resources for free — enter your email and I'll send it right away.

Checklist

Pre-engagement checklist: 20 questions to gauge a vendor's technical strength

When you outsource development, the gap in technical ability shows before kickoff, not after delivery. Drawn from single-handedly designing and operating a METI Minister's Award–winning product, these are 20 questions — across design, security, testing, operations, and contracts — that reveal a vendor's true ability.

What's inside

  • 1. Design & architecture (4 items)
  • 2. Security (4 items)
  • 3. Testing & quality (4 items)
  • 4. Operations & infrastructure (4 items)
  • 5. Contract & process (4 items)

E-posta ile ücretsiz indirin

Checklist

DX self-assessment worksheet: 25 checks to find where to start fixing your Excel & fax workflows

Twenty-five checks to work out for yourself — no technical background required — where to start with the workflows currently running on Excel, fax, and paper. Moving through inventory → priority scoring → "off-the-shelf SaaS or custom build" → cost-effectiveness → funding, you end up able to state, in your own words, the first process to fix and the most you should spend on it. It turns the exact lens I apply in the free 30-minute DX assessment into a worksheet — bring your answers to the free assessment (/pricing#dx-assessment) to have them sanity-checked.

What's inside

  • 1. Inventory your workflows (5 items)
  • 2. Score the bottlenecks (5 items)
  • 3. Decide the move — off-the-shelf SaaS, custom build, or not yet (5 items)
  • 4. Rough out the cost-effectiveness (5 items)
  • 5. Funding and how to proceed (5 items)

E-posta ile ücretsiz indirin

Checklist

AI-generated code security self-audit checklist (vibe coding edition)

Apps built with Cursor, Claude Code, v0, Lovable, or Bolt run surprisingly well on the happy path. What production tests is how they behave against malformed input and legitimate requests that point at someone else's ID. This checklist gives you 25 self-checks across five areas — authorization, Supabase RLS, input validation, secrets, and pre-release gates — to run with your own hands before going public. Part of the horizontal controls can be automated with the free OSS npx @aegiskit/cli scan (/aegis); the vertical risks — authorization and RLS design — are what this list makes you verify with your own eyes.

What's inside

  • 1. Authorization & IDOR (5 items)
  • 2. Supabase RLS (5 items)
  • 3. Input validation & injection (5 items)
  • 4. Secrets & environment variables (5 items)
  • 5. Pre-release gates (5 items)

E-posta ile ücretsiz indirin