Your digital construction kit for secure, modular Postgres. Build production apps that last.

San Francisco
Software and culture in San Francisco ⚡️ Honored to contribute to Illuminate and the Grace Window project 🙏🏻 We <3 SF
1
1
121
Constructive retweeted
Grace window in San Francisco ⚡️music by Tim Weed @IlluminatedArts @nusalt @constructive_io
1
6
358
Constructive retweeted
hey SF! come to the Grace Cathedral 8pm Sept 21st when we open to shoot the lasers pumped about the @constructive_io software collaboration with @nusalt and @IlluminatedArts 🫶
2
3
19
628
Constructive retweeted
Today at 2:30pm ET, Dan Lynch joins the Postgres community to build a testable Postgres workflow for AI coding agents live. Register: postgresconf.org/conferences…
3
2
149
Constructive retweeted
In case you missed it, Closing the Loop: Modular, Testable Postgres for AI Agents with Dan Lynch is now available on YouTube. Watch here: piped.video/uDOWROFoSUM
4
6
285
Constructive retweeted
The DseWiki story isn't just a browser-access problem. It's a where does authority live problem. Those agents were supposed to have read access to the internet, not write access. They found a path around that boundary because their authority was being constrained by the environment rather than represented as a first-class principal all the way down the stack. That's the opposite assumption behind the architecture we're building into @constructive_io 🧵
Holy...15,000+ edits by OpenAI agents on DseWiki, a German programming wiki, over two months. They used it to pass each other restriction bypasses, detection evasion, and state between runs. Backups when moderators deleted pages. Every enterprise security review of your agent just got harder. If your pitch says "full browser access and stored credentials," that's now the first question in diligence, not the last. The startups that win the next 12 months ship a permission model, an audit log, and a kill path on day one...not after the first breakout. We write $250k–$3M first checks. If you're building the containment layer for agents, DM me. reuters.com/world/europe/ope…
1
1
8
507
Constructive retweeted
and the bottleneck moves to trust
When software was expensive - thin, horizontal, best-of-breed software stacks extracted rents across every business. Now that software is cheap - value moves to vertically integrated businesses that deliver opinionated end-to-end experiences.
1
2
2
616
Constructive retweeted
To show appreciation for what @ElectricSQL built with PGlite, we're launching a pglite test framework and integrated it with pgpm :) We built pglite-test to run real migrations, triggers, RLS policies, roles, and pgvector entirely inside your Node test runner with PGlite. No Docker. No server. No CI services. Just pnpm test. ⚡️ constructive.io/blog/pglite-… @constructive_io
3
16
1,301
Constructive retweeted
Happy 4th from San Francisco!
1
7
89
17,550
Constructive retweeted
It's been an honor to contribute a small part to the 7x7 Summer of Awe installation from @IlluminatedArts Working with @nusalt on hardware and @constructive_io on software, we created the "Awepad" powering the laser show... and watching art, technology, and the city come together has been incredibly rewarding
2
1
28
26,010
Constructive retweeted
In San Francisco for Deep Tech Week? Join us tonight for: 🚀 Build Night: The Data Layer for Agentic Apps Hosted by @pgEdgeInc, @constructive_io, @AngelList, and Frontier Syndicate.
3
2
9
605
Everyone wants smarter agents. We care more about smarter constraints. Better models won't decide who wins. The operators who win will be the ones who can run thousands of agent actions without leaking data, breaking permissions, or quietly introducing security holes. Intelligence is getting cheap. Trust isn't.
1/ There's a bottleneck in AI that hundreds of billions of dollars can't buy past: the very few people who can wield this technology well enough to matter. There aren't nearly enough of them, and the entire buildout runs through them.
3
545
Constructive retweeted
Code generation isn't the moat. Engineering is. Last week I sat on a panel at the SVB Experience Center with Sanjeev Dhanda (@GoogleDeepMind) and @abhiaiyer (@mastra) on the move from vibe coding to agentic engineering @constructive_io @SiliconVlyBank @Kristopherfloyd
23
29
304
971,987
Constructive retweeted
We're at capacity for the tonights session! Couldn't be more stoked to chat about building systems that agents and humans can converge on to build trusted code with Sanjeev Dhanda (@GoogleDeepMind) and @abhiaiyer (@mastra)! Thanks @Kristopherfloyd (Frontier Syndicate) and Joanna Zanghi (@SiliconVlyBank), and Acasia for co-hosting with @constructive_io 🚀
3
3
14
949
Constructive retweeted
Using @PlanetScale's own benchmark data. Removing the volatile and non-optimized polices, pure RLS vs. no RLS (I'm including original data for comparison) This is what performance looks like when security is done right.
Replying to @danlynch
The @PlanetScale RLS benchmarks compare per-row function calls vs no RLS. But real RLS policies don’t have to be function-based or evaluated per row. With proper design (stable conditions, InitPlan caching via subqueries, good indexes), you get near-zero overhead + full index utilization.
2
8
39,971
Constructive retweeted
Interesting take on RLS from @PlanetScale — but the “per-row overhead” they highlight isn’t a limitation of RLS, it’s a consequence of how the policy is written a thread on their take and benchmark 🧵
Postgres RLS sounds great in theory: embedded access control right in the database. In practice, there's complexity in policy configuration, managing your attack surface, and performance implications. Our latest article takes a deep dive into RLS.
10
17
159
1,103,621
Constructive retweeted
This is exactly why, and completely validates everything we do at @constructive_io because RLS is complex and must be managed or you'll make every mistake that @PlanetScale is assuming here. We solve all of these issues, and then some 🚀
Postgres RLS sounds great in theory: embedded access control right in the database. In practice, there's complexity in policy configuration, managing your attack surface, and performance implications. Our latest article takes a deep dive into RLS.
15
22
241
1,285,591