Frank S. Rietta at the 2022 Rails SaaS conference Los Angeles, CA.

Frank Rietta

I'm an American computer scientist and cybersecurity professional located in Alpharetta, Georgia. I lead Rietta Inc. as founder and CEO since 1999, and I founded Atlanta Ruby Developer, Rietta's Ruby on Rails development division, in 2012. My work also involves public speaking, providing security training for developers, and acting as an Expert Witness. I've been publicly teaching software security since 2014, work that now continues through Rietta Learning and the Rietta On Security newsletter. I hold an M.S. in Information Security (Cyber Security), am a lifetime OWASP member, and have earned a black belt in Hapkido. Beyond my career, I'm a husband and father. My full professional bio, including media appearances and legislative testimony, lives at rietta.com.

Highlights from Recent Articles

Sunset Trap (Software)

In software development and devsecops, the term sunset trap refers to a "production down" disruptive event caused by an unknown or forgotten third party dependency. It is linked to an unnoticed deprecated with replacement. I touched on this subject recently with my latest iteration of teaching software dependency management techniques in Beware the Sunset Trap: Why Your Legacy Software is a Ticking Time Bomb (and AI is Lighting the Fuse) on the Rietta blog!

Local AI Setup on my Ubuntu Linux Workstation

Seems everyone is into artificial intelligence these days. I am digging into it but taking a different path from the crowd. While others are paying for ChatGPT subscriptions and chasing models, I am methodically pushing the limits of what can be done locally. Protecting data is going to depend on a local AI use case. Read more about my set up at Local AI Setup with Ollama and Nvidia GPU on Ubuntu Linux

Code Review & Air Gaps

I was recently able to share some details from some security assessment work we did for a desktop client/server application that runs in an air gap environment. Some pretty interesting use of the MASVS. Check it out at Securing the Unconnected: Air Gap Windows Application Code Review and Developer Training Success.

The Five Pillars of InfoSec

Rietta is a cybersecurity firm, so why have my last few posts been about missing document titles and metadata in government PDFs? I laid out the reasoning in my latest post: accessibility failures are availability failures, one of the five pillars of information security alongside confidentiality, integrity, non-repudiation, and authentication, and detecting them at scale is exactly what our industry already does. First in a series covering each pillar. Read it at The Five Pillars of Information Security (And Why We Audit Accessibility) on the Rietta blog.

Threat Modeling for ADA/WCAG Compliance

Most organizations treat digital accessibility as a content problem: someone finds a missing alt tag, fixes it, and moves on. I think that's the wrong frame entirely, it's an organizational risk and governance gap, and the right tool for the job is the same threat modeling and risk-scoring discipline we already use for application security. Read more at Threat Modeling for ADA/WCAG Compliance on the Rietta blog.

Meet Titan, the AI Research Lab Server

We built a new dual-GPU AMD workstation, Titan, to run the local models and document classifiers behind Metadata Minder's ADA Title II and WCAG 2.1 scanning, with the OS and data volumes deliberately unlocked by two different keys so the machine can survive an unattended reboot without ever exposing the data itself. Read the full build story, RAID hiccups and all, at Meet Titan, the Rietta AI Research Lab Server on the Rietta blog.

Exciting Research

Metadata Minder

Updated 7/27/2026

At Rietta, we have been working with government clients to achieve ADA compliance. As we did this work, we learned that many public sector organizations do not know what documents they have published, which have the legally required metadata tags, and which are leaking potentially sensitive information. Metadata Minder uses document intelligence built on local software and local AI models to answer these questions at scale.

The initial free pilot program has ended. If your organization needs corpus-wide analysis of published documents, reach out at Metadata Minder.

Video Learning

That teaching now lives at Rietta Learning, a growing video library covering application security and secure development practices.

For shorter clips, I also post to my @frankrietta YouTube Channel Shorts. Here is one on what a CVE is in Software Security.

Rietta On Security Newsletter

I write Rietta On Security, a newsletter with one substantive email a month. No drip campaign, just the security and software development topics I think are worth your time.

Booking Me for an Event

I am an active CEO for a technology company. However, I am available for special training engagements for your team. You can inquire via the contact page at Rietta.com.

My Related Websites and Social Media

Tech Community Volunteerism