<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel><title>Jobbit Security Blog</title><link>https://jobbitsecurity.com/blog/</link><description>Practical guides and briefings from Jobbit Security on penetration testing, red teaming, cloud security, phishing simulation and Cyber Essentials or ISO 27001 readiness for UK businesses.</description><language>en-gb</language><lastBuildDate>Sat, 19 Sep 2026 09:00:00 +0000</lastBuildDate><atom:link href="https://jobbitsecurity.com/blog/feed.xml" rel="self" type="application/rss+xml"/><item><title>What Is Jobbit? A Security Lead&#x27;s Guide to the AI Agent Platform Behind Jobbit Security (2026)</title><link>https://jobbitsecurity.com/blog/what-is-jobbit-security-leads-guide-2026/</link><guid isPermaLink="true">https://jobbitsecurity.com/blog/what-is-jobbit-security-leads-guide-2026/</guid><pubDate>Sat, 19 Sep 2026 09:00:00 +0000</pubDate><description>Jobbit is the UK AI agent and human network at jobbit.uk, and Jobbit Security is its in-house penetration testing practice. Here is what the platform does, why an AI company runs its own red team, and the five questions to ask any agent platform before you connect it to your business.</description><category>AI agents</category><category>Jobbit</category><category>Security guidance</category><content:encoded><![CDATA[<p>If you are the person a business turns to before it connects a new tool to its email, its files or its bank, "what is Jobbit?" is a fair first question, and "what does it do with our data?" is the right second one. This post answers both from the security side of the company, and then gives you the five questions we would ask any AI agent platform, including ours, before letting it near a live business.</p>
<p>The full company page is on the main site: <a href="https://jobbit.uk/en/blog/what-is-jobbit-ai-agent-human-network-2026" target="_blank" rel="noopener">What Is Jobbit? Inside the UK AI Agent and Human Network</a>. What follows is the short version, with the security lens on.</p>
<h2 id="jobbit-in-sixty-seconds">Jobbit in sixty seconds</h2>
<p>Jobbit is a UK company with three connected divisions.</p>
<ul><li><strong><a href="https://jobbit.uk/" target="_blank" rel="noopener">Jobbit.uk</a></strong> is an AI agent and human network. You describe a job in plain language and the agent builds the web app, runs the automation, writes the document, does the research or makes the media. When a task needs a person, it hands the job to a vetted expert on <strong><a href="https://pro.jobbit.uk/" target="_blank" rel="noopener">Jobbit Pro</a></strong>, with payment held in escrow until the work is accepted. The company&#x27;s guide to <a href="https://jobbit.uk/en/blog/12-jobs-an-ai-agent-can-do-for-your-business-2026" target="_blank" rel="noopener">the 12 jobs an AI agent can do for a business this week</a> is the practical tour.</li><li><strong><a href="https://jobbitlabs.com/" target="_blank" rel="noopener">Jobbit Labs</a></strong> is the research division. It records, with consent, how real-world work is done on the platform and builds datasets, evaluations and world models on that data for AI and robotics teams.</li><li><strong>Jobbit Security</strong>, this site, is the offensive security practice: manual penetration testing, cloud security assessment, red team operations, phishing simulation and vCISO support for UK businesses, aligned to OWASP, NIST SP 800-115, PTES and MITRE ATT&amp;CK.</li></ul>
<p>One company, one team in London, one loop: work is assigned and executed on jobbit.uk, what it teaches goes to Labs, and Security keeps the whole system tested.</p>
<h2 id="why-an-ai-company-runs-its-own-red-team">Why an AI company runs its own red team</h2>
<p>Two reasons, and both are worth understanding before you trust any agent vendor.</p>
<p>First, the agent platform and the data engine handle customers&#x27; code, files and operations. A company in that position should be tested by people who are trying to break it, and we would rather that team was ours than someone else&#x27;s. Jobbit&#x27;s stated principle is "test yourself first": offensive security runs on our own systems before it is sold to anyone.</p>
<p>Second, the same AI that lets a business build an app in an afternoon lets an attacker find that app&#x27;s weaknesses in an hour. Attack tooling has become faster and cheaper at exactly the moment more small businesses are shipping software they did not write by hand. A company that builds with AI should be able to defend with it, and that expertise has to live somewhere. It lives here.</p>
<h2 id="five-questions-to-ask-any-agent-platform">Five questions to ask any agent platform</h2>
<p>Vendors will answer the questions you ask. These are the ones worth asking, with what Jobbit says about each, so you can hold us to the same standard.</p>
<h3 id="1-where-does-the-work-run-and-who-hosts-what-it-produces">1. Where does the work run, and who hosts what it produces?</h3>
<p>An agent that builds a website or an automation has to run it somewhere. Ask whether the output lives on the vendor&#x27;s infrastructure, yours, or a third party&#x27;s, and how you would move it. Jobbit builds and hosts web apps on its own hosting, keeps task runs and files in your workspace, and states plainly that the files, the code and the exports are yours to take with you.</p>
<h3 id="2-what-is-retained-and-what-is-used-for-training">2. What is retained, and what is used for training?</h3>
<p>This is the question most often skipped. Ask what the platform keeps after a task ends, whether it is used to train models, and whether you can opt out. Jobbit&#x27;s answer is that records of how tasks are done are captured inside the platform with the customer&#x27;s consent and with clean provenance, nothing is scraped, and the same records feed <a href="https://jobbitlabs.com/" target="_blank" rel="noopener">Jobbit Labs</a> only on that basis.</p>
<h3 id="3-if-humans-are-involved-how-are-they-vetted-and-paid">3. If humans are involved, how are they vetted and paid?</h3>
<p>An agent that hands work to people has just widened your supply chain. Ask who those people are, how they are vetted, what they see, and what protects payment. On Jobbit, experts come from the vetted <a href="https://pro.jobbit.uk/" target="_blank" rel="noopener">Jobbit Pro</a> network, the agent drafts a scoped brief, and payment sits in escrow until the work is accepted, so both sides have a record and a remedy.</p>
<h3 id="4-what-can-the-agent-reach-and-how-is-that-scoped">4. What can the agent reach, and how is that scoped?</h3>
<p>Agents are useful because they act. That is also the risk. Ask how credentials are stored, whether the agent can browse or log in to accounts, and how you limit what a single task can touch. Jobbit&#x27;s <a href="https://jobbit.uk/en/blog/jobbit-projects-shared-files-instructions-secrets-2026" target="_blank" rel="noopener">Projects feature</a> keeps shared files, instructions and secrets together per project, and its <a href="https://jobbit.uk/en/blog/jobbit-agent-browser-watch-and-take-control-2026" target="_blank" rel="noopener">agent browser</a> lets you take control and hand back mid-run. Whatever platform you choose, give it its own least-privilege accounts rather than your own.</p>
<h3 id="5-how-do-you-get-everything-out">5. How do you get everything out?</h3>
<p>The exit is part of the entrance. Ask whether exports are complete and in open formats, and whether hosting can be moved. Jobbit&#x27;s pricing pages and its company post commit to no lock-in: free means free, no watermark, and your work leaves with you. Test that promise with a small project before you rely on it.</p>
<h2 id="a-safe-first-month-with-an-agent">A safe first month with an agent</h2>
<p>Whichever platform you pick, the same habits keep the blast radius small while the business learns what the agent is good at.</p>
<ul><li><strong>Start with tasks that need no access.</strong> Documents, research, images and the <a href="https://jobbit.uk/tools" target="_blank" rel="noopener">free online tools</a> prove the workflow without touching a single account. Our companion post on <a href="/blog/free-online-tools-client-data-safety-checklist-2026/">free online tools and client data</a> covers the file-handling side.</li><li><strong>Create separate credentials.</strong> A dedicated mailbox, API keys with the minimum scopes, and a separate card if the agent will ever buy anything.</li><li><strong>Review automations before they run on a schedule.</strong> Read what a scheduled task does, and who it emails, before it does it every Monday.</li><li><strong>Keep a human approval step for money and outbound messages.</strong> Drafting is cheap; sending is not reversible.</li><li><strong>Read the run log.</strong> Jobbit keeps task runs in the workspace. Ten minutes a week reading what the agent actually did teaches you more than any policy document.</li><li><strong>Rotate anything you pasted into a chat by mistake.</strong> Treat a secret in a prompt like a secret in a ticket.</li></ul>
<p>None of this is specific to Jobbit. It is what we would tell a client about any agent, and what we check when we test one.</p>
<h2 id="where-jobbit-security-fits">Where Jobbit Security fits</h2>
<p>When a business has moved past the first month and the agent is building real things, the question changes from "can we trust it?" to "can we prove it?". That is a penetration test: manual, depth-first testing of the web apps, APIs, cloud accounts and automations the business now depends on, including the ones an agent built. We <a href="/#services">test the full attack surface</a>, work under NDA at a fixed scope and price, and write the report for the people who have to fix things and for the board that has to sign off the budget.</p>
<p>If that is where you are, <a href="/#contact">book a scoping call</a>. A consultant replies within one working day.</p>]]></content:encoded></item><item><title>Free Online Tools and Client Data: A Safety Checklist for PDFs, QR Codes, Images and Invoices (2026)</title><link>https://jobbitsecurity.com/blog/free-online-tools-client-data-safety-checklist-2026/</link><guid isPermaLink="true">https://jobbitsecurity.com/blog/free-online-tools-client-data-safety-checklist-2026/</guid><pubDate>Sat, 19 Sep 2026 09:00:00 +0000</pubDate><description>Every small business compresses PDFs, prints QR codes, resizes photos and sends invoices with free online tools. Each one is a data-handling decision. Here are the four risks hiding in free, a checklist per tool, and how Jobbit&#x27;s free tools handle your files.</description><category>Security guidance</category><category>Small business</category><category>Free tools</category><content:encoded><![CDATA[<p>Every small business runs on free online tools. A contract gets compressed before it goes to a client. A menu gets a QR code. A product photo gets resized for a listing. An invoice gets made from a template. None of these feel like security decisions, and all of them are: each one moves client data through a service you have not read the terms of, in a format you may not fully control.</p>
<p>This is the checklist we give clients when we review how a business handles its everyday documents. It is short, it is practical, and it ends with how the <a href="https://jobbit.uk/tools" target="_blank" rel="noopener">free tools on jobbit.uk</a> handle the same jobs, because Jobbit Security is part of the company that built them and we would rather explain the trade-offs than pretend there are none.</p>
<h2 id="the-four-risks-hiding-in-free">The four risks hiding in "free"</h2>
<p><strong>Uploads leave your machine.</strong> The moment you drop a PDF on a compressor&#x27;s website, the file is on someone else&#x27;s server. Some tools delete it within the hour. Some keep it to train models or to serve advertising. Many say nothing at all. A tool that is free and has no visible business model is being paid for somehow, and the file is often the currency.</p>
<p><strong>QR codes can point anywhere.</strong> A printed code is a link you cannot read. Dynamic codes, the kind most free generators default to, route through the provider&#x27;s server first, which means the destination can change or expire without the code changing. Attackers exploit the same blindness by sticking their own codes over legitimate ones on parking meters, menus and posters, a technique called quishing.</p>
<p><strong>Images carry more than pixels.</strong> A photo from a phone usually contains EXIF metadata: the time, the device, and often the GPS coordinates of where it was taken. Resize a photo of your home office for a listing and a careless tool will publish your home address in the file.</p>
<p><strong>Invoices are an attack surface.</strong> Invoice fraud, often called mandate fraud, is one of the most common ways UK businesses lose money: a criminal impersonates a supplier and asks for the bank details on file to be changed. Editable invoice files, inconsistent numbering and templates reused across clients all make the impersonation easier and harder to spot.</p>
<h2 id="checklist-compressing-and-sharing-pdfs">Checklist: compressing and sharing PDFs</h2>
<ul><li>Read the retention line before you upload. If you cannot find it in thirty seconds, assume the file is kept.</li><li>Sort documents into three bins: public, internal, and regulated or privileged. Only the first bin goes to an anonymous free tool.</li><li>Prefer tools that work inside an account you control, so there is a record of what was uploaded and by whom.</li><li>Check the output. Aggressive compression can turn a signature or a small-print clause into an unreadable smudge, which is its own problem when the document is a contract.</li><li>Compress once, at the end. Repeated compression compounds the damage.</li></ul>
<p>The jobbit.uk guide to <a href="https://jobbit.uk/en/blog/compress-pdf-free-no-upload-limit-2026" target="_blank" rel="noopener">compressing a PDF for free with no upload limit</a> covers the size-versus-legibility trade-off in detail.</p>
<h2 id="checklist-qr-codes-on-anything-you-print">Checklist: QR codes on anything you print</h2>
<ul><li>Use static codes for print. A static code encodes the final address, so nothing can be changed after the poster goes up and nothing expires when a subscription lapses.</li><li>Point codes at a domain you own, never at a shortener you do not control.</li><li>Keep a register of every code you have printed, where it is, and what it points to.</li><li>Scan your own codes in the wild every few months. If the destination is not yours, someone has covered it.</li><li>Tell staff that a code on a poster, a parking meter or an email attachment is a link from a stranger, and to treat it that way.</li></ul>
<p>The <a href="https://jobbit.uk/en/blog/free-qr-code-generator-no-expiry-2026" target="_blank" rel="noopener">free QR code guide on jobbit.uk</a> explains why most free codes stop working and how to make one that does not.</p>
<h2 id="checklist-resizing-and-publishing-images">Checklist: resizing and publishing images</h2>
<ul><li>Strip metadata on export. Check the output file&#x27;s properties before it goes on a listing, a job advert or social media.</li><li>Be deliberate about what is in the frame: screens, whiteboards, paperwork and door numbers all leak.</li><li>Keep originals in a controlled folder, and publish only the resized copies.</li><li>For staff photos, get consent for the specific use, not a blanket one.</li></ul>
<p>Formats and platform sizes are covered in the <a href="https://jobbit.uk/en/blog/resize-images-free-heic-to-jpg-2026" target="_blank" rel="noopener">image resizing guide</a>.</p>
<h2 id="checklist-invoices-that-cannot-be-tampered-with">Checklist: invoices that cannot be tampered with</h2>
<ul><li>Send PDFs, not editable documents, and never a template with other clients&#x27; details left in.</li><li>Number invoices sequentially and state your bank details the same way every time, so a change stands out.</li><li>Put a line on every invoice saying that you will never change bank details by email, and ask customers to phone a known number if they receive such a request.</li><li>Do the same in reverse: verify any supplier&#x27;s change of details by calling a number you already hold, not one in the message.</li><li>State payment terms and statutory late-payment interest clearly. An invoice that reads like it was produced by a process is harder to impersonate than one that reads like a favour.</li></ul>
<p>The <a href="https://jobbit.uk/en/blog/how-to-write-an-invoice-free-template-uk-2026" target="_blank" rel="noopener">invoice guide on jobbit.uk</a> lists the nine fields a UK invoice needs and the late-payment terms that get it paid.</p>
<h2 id="how-jobbit-s-free-tools-handle-the-same-jobs">How Jobbit&#x27;s free tools handle the same jobs</h2>
<p>Jobbit&#x27;s four tools, a <a href="https://jobbit.uk/tools/qr-code" target="_blank" rel="noopener">QR code generator</a>, a <a href="https://jobbit.uk/tools/compress-pdf" target="_blank" rel="noopener">PDF compressor</a>, an <a href="https://jobbit.uk/tools/resize-image" target="_blank" rel="noopener">image resizer</a> and an <a href="https://jobbit.uk/tools/invoice" target="_blank" rel="noopener">invoice generator</a>, are forms that send a single message to the Jobbit agent, which does the job inside your own workspace and hands the file back. The overview post, <a href="https://jobbit.uk/en/blog/jobbit-free-tools-qr-pdf-image-invoice-2026" target="_blank" rel="noopener">four free online tools on jobbit.uk</a>, links all of them.</p>
<p>Against the checklist above, this is what you get and what you should still do:</p>
<ul><li><strong>Account, not anonymity.</strong> The tools run on the free plan with no card, but inside an account, so there is a record of what was done. Jobbit&#x27;s stated principle is that your files, code and exports are yours to take with you.</li><li><strong>Consent for training.</strong> Records of how tasks are done are used to improve the agent only with consent and clean provenance. Nothing is scraped. Read the terms before you rely on that for regulated material, as you would with any provider.</li><li><strong>Static QR codes.</strong> The QR tool makes static codes that encode the final address and never expire, in PNG and SVG, which is the right default for print.</li><li><strong>Sensible defaults for the rest.</strong> PDFs to a target size with legible text, images to exact platform dimensions, invoices with the nine UK fields and payment terms. Check the output as you would from any tool.</li></ul>
<p>We say all of this as the team that tests Jobbit&#x27;s own systems. The company&#x27;s principle is "test yourself first", and the reasons it runs an in-house red team are set out in our post on <a href="/blog/what-is-jobbit-security-leads-guide-2026/">what Jobbit is, from a security lead&#x27;s point of view</a>.</p>
<h2 id="when-a-free-tool-is-the-wrong-answer">When a free tool is the wrong answer</h2>
<p>Some material should never go through a shared online service of any kind: health records, legally privileged documents, payroll files, anything covered by a client&#x27;s own security schedule. For those, use tooling that runs on your own machines or under a contract that names retention, location and deletion. And if a business is handling client files at volume, the question is no longer which free tool to use but whether the process around them has ever been tested.</p>
<p>That is what we do. If you would like a second pair of eyes on how your business handles documents, uploads and payments, <a href="/#contact">book a scoping call</a>. No obligation, and a consultant replies within one working day.</p>]]></content:encoded></item></channel>
</rss>
