Pelle Forsman

Aug 10, 2026 · first shared on LinkedIn

Before anyone else moves into my platform, I attacked it 11 different ways

I am building a platform where digital characters live: AI characters that exist only online, post their own content, and live through their own storylines. Today it runs my own characters. But it is built to hold more than one customer, and that raises the question every software owner should lose sleep over: when a second customer signs in, can they see anything that belongs to the first?

I did not want to guess. So I attacked it myself.

Why would you break into your own product?

Because the alternative is that someone else does it first.

Most people test whether their product works. Click the buttons, watch the happy path, ship it. Far fewer test whether it holds when someone leans on it. And the moment you hold work that belongs to a customer, that second test is the one that matters. Their characters, their images, their costs, their history. If one customer can read another’s, you do not have a platform. You have an incident waiting for a date.

What did the break-in look like?

I made a second account and played burglar against myself.

Then I tried to read everything that belongs to the first account: its characters, its images, what it has spent, and the full record of where every image came from. 11 different attempts, and not through some secret side entrance either. Every attempt went through the exact same doors a real customer would use every day.

All 11 were blocked. Not one attempt got a single item back.

That number matters more to me than any feature I shipped this month. A feature tells you what the product can do. A failed break-in tells you what the product will not do, even when pushed.

A rule only counts if it survived an attack

Here is the part I actually want you to steal. The safety rules in the platform are not a checklist somebody wrote in a document. Each one is enforced by the system itself, and each one earned its place the same way: I tried to break it, and it held.

  1. Can a character go live before its rulebook is locked? No. Every character has a fixed rulebook, who they are, how they look, how they speak, and nothing publishes until it is locked.
  2. Can a locked face be quietly swapped for a new one? No. Once a character’s face is set, the system refuses to replace it.
  3. Can a character based on a real person exist without signed consent? No. If it is modeled on someone real, the consent has to exist first or the images cannot exist at all.
  4. Can a story run before a human says yes? No. Every storyline waits for an explicit human approval.

There is even a rule for the calendar. The characters live through real events, and the platform now carries 57 of them, every date checked against official sources. A story moment that rides a real event cannot be approved until its legal limits are acknowledged in writing.

And the system applies the rules to me too. One character’s first season is fully written, and the platform refuses to run it, because her rulebook is not finished yet. That refusal is not a bug. That is the product doing its job on its own owner.

What is the lesson for your business?

Think of it like a hotel. You do not prove the rooms are safe by trusting the staff. You prove it by trying every key in every door, before the guests arrive.

Whatever you run, there is a version of this test. Try to see another customer’s data. Try to skip your own approval step. Try to publish something that should be blocked. If a rule cannot survive you attacking it on purpose, it will not survive an accident either.

I build AI agents that run all parts of my online business. Check them out at pelleforsman.com.

← All posts