The reference shelf
PlainDefinitions
Over a hundred terms this work involves, defined properly and without selling anything. If a client has to nod along to a word, we have not explained it.
AI and language models · 36 terms
Prompt injection
An attack where text the model reads as data is treated by it as instructions instead.
RAG (retrieval-augmented generation)
Looking up relevant documents first and putting them in the prompt, so the model answers from your material instead of from memory.
Embedding
A list of numbers representing a piece of text, arranged so that texts about similar things end up close together.
Vector database
A database built to find the stored items whose embeddings are closest to a query's, quickly, across millions of rows.
Large language model (LLM)
A model trained on enormous amounts of text to predict what comes next, which turns out to be enough to write, summarise, translate and reason through many tasks.
Context window
The maximum amount of text a model can take into account at once, counting the instructions, the conversation and the answer together.
System prompt
The standing instructions sent ahead of every conversation, setting what the model is supposed to do and how it should behave.
Hallucination
A confident, fluent, entirely invented answer — a citation, a figure or an API that does not exist.
Fine-tuning
Continuing to train an existing model on your own examples, so it adopts a behaviour or a style it did not have.
LoRA (low-rank adaptation)
A way of fine-tuning that trains a small add-on layer instead of the whole model, producing a file of a few megabytes rather than a few gigabytes.
AI agent
A language model given tools it can call and a goal to pursue, so it decides the steps rather than following a fixed script.
Tool calling
The mechanism by which a model asks the surrounding application to run a named function, and gets the result back as text.
MCP (Model Context Protocol)
An open protocol for exposing tools and data to a model, so one integration works with any client that speaks it.
Evaluation (evals)
A repeatable test set that measures whether a change to an AI system made it better or worse, rather than just different.
Stable Diffusion
A family of open-weight image models that generate a picture by repeatedly removing noise from a random start, guided by a text description.
ComfyUI
A node-based interface for image generation, where the pipeline is an explicit graph rather than a text box with hidden defaults.
n8n
An open-source workflow-automation tool that connects apps, APIs and AI models into repeatable pipelines — self-hostable, so data can stay on your own infrastructure.
Token
The unit a language model reads and writes — a word fragment, word or punctuation mark — and the unit its cost and context limits are counted in.
Temperature
A sampling setting that controls how random a language model's output is — low values pick the most likely words, high values take more chances.
Transformer
The neural network architecture behind modern language models — attention layers that weigh which earlier words matter when predicting the next one.
Prompt engineering
The practice of writing model inputs so the output is reliably what you need — structure, examples, constraints and tone rather than hope.
Few-shot prompting
Teaching a model a task by putting examples of it inside the prompt — input and desired output pairs — instead of describing the task in words.
Chain of thought
Prompting a model to reason step by step before answering — accuracy on multi-step problems improves when the working is generated, not skipped.
AI guardrails
The checks around a model that constrain what it can say and do — input filters, output validation, permissioned tools — so a bad response fails safely.
AI chatbot
A conversational interface backed by a language model — useful when it answers from your real data and hands off gracefully when it cannot.
Knowledge base
The maintained, structured store of facts a system answers from — documents, prices, policies — that a chatbot grounds on so it can only say what is true.
Workflow automation
Making a repeated business process run itself — a trigger starts it, steps move the data between systems, and exceptions reach a human.
Zapier
The best-known no-code automation platform — connects SaaS apps with trigger-action 'Zaps' without servers to run, priced per task.
CRM automation
Wiring the customer database so leads, follow-ups and status changes happen automatically — enquiry lands, lead is created, the right person is pinged.
Multimodal model
A model that takes and produces more than text — images, audio, documents — so 'what is wrong in this photo' or 'read this invoice' is one call.
Speech to text
Transcribing spoken audio into written text with a model — the front end of voice notes, call summaries and 'talk to the computer' interfaces.
OCR
Optical character recognition — turning images of text into real text, so scanned invoices, receipts and forms become data instead of pictures.
Diffusion model
The image-generation architecture that starts from noise and removes it step by step — the engine behind Stable Diffusion and most modern image tools.
LangChain
A popular framework for building LLM applications — chains and agents that wire models to data sources, tools and memory.
Grounding
Tying a model's answers to real sources — retrieved documents, databases, live data — so it states what is true instead of what sounds right.
Agentic workflow
A pipeline where a model does not just answer but acts — calls tools, checks results, retries — inside a loop with real boundaries.
Security · 33 terms
Purple team
Running the attack and the defence as one exercise, so every fix is verified against the technique that found the hole.
Red team
The offensive side: people whose job is to get in, using whatever an actual attacker would use.
Blue team
The defensive side: hardening the systems, watching them, and handling it when something happens.
Penetration test
An authorised, scoped attempt to break into a system, done to find out what an attacker could actually achieve.
OWASP LLM Top 10
A community list of the most significant security risks specific to applications built on large language models.
OWASP Top 10
The long-standing community list of the most critical web application security risks, revised every few years.
Data exfiltration
Getting data out of a system that was not supposed to let it leave.
Threat model
A written answer to who would attack this, what they would want, and what would actually stop them.
Security audit
A systematic review of a system against a standard or a set of criteria, aiming for coverage rather than for a way in.
Incident response
The plan and the practice for what happens between noticing something is wrong and being back to normal.
Rate limiting
A control that caps how many requests a client can make in a time window — the basic defence against brute force, scraping, abuse and runaway API costs.
Cross-site scripting (XSS)
An attack that injects hostile JavaScript into a page other people view — the browser runs the attacker's code with the victim's session.
CSRF
Cross-site request forgery — tricking a logged-in browser into sending a request the user never meant, riding on their cookies.
SQL injection
Smuggling database commands through input fields — the attack that turns 'name' into 'show me every user's password hash'.
MFA / 2FA
Multi-factor authentication — proving identity with something you know plus something you have, so a leaked password alone cannot log in.
Password hashing
Storing a one-way, salted, deliberately slow fingerprint of each password — so a stolen database is a puzzle, not a list.
JWT
JSON Web Token — a signed, self-contained credential a server can verify without a database lookup; the standard way APIs say 'this request is you'.
OAuth
The authorization protocol behind 'Sign in with Google' — lets a service act on your behalf with a scoped token instead of your password.
Session hijacking
Stealing the token that proves a logged-in session — whoever holds it is you, no password needed.
Encryption at rest
Encrypting data where it is stored — disks, databases, backups — so a stolen drive or leaked dump is ciphertext, not data.
TLS
Transport Layer Security — the encryption layer behind HTTPS that keeps traffic private and proves the site you reached is the site you meant.
Zero trust
A security model that trusts nothing by default — every request is verified by identity and context, even inside the network.
Least privilege
Every user, service and process gets only the access the job requires — nothing more, so a compromise has a small blast radius.
Security headers
HTTP response headers that tell browsers how to handle the page safely — HSTS, CSP, X-Frame-Options — free defences most sites skip.
Content Security Policy
A header that whitelists where a page's scripts, styles, images and connections may come from — the second wall that stops XSS even when injection happens.
Supply-chain attack
Attacking you through something you trust — a poisoned dependency, a compromised build tool — instead of attacking you directly.
SBOM
Software bill of materials — the inventory of every component and version inside a piece of software, so 'are we vulnerable to X' is a lookup, not an excavation.
Secrets management
Keeping API keys, passwords and certificates out of code and chat — in a vault, rotated, access-logged — so one screenshot is not a breach.
Ransomware
Malware that encrypts your files and sells the key back to you — the attack where your backups decide whether it is a bad week or a closed business.
Phishing
Tricking people into handing over credentials or clicking the payload — the front door of most breaches, because it attacks the part that cannot be patched.
GDPR
The EU's data-protection regulation — consent before collection, rights to access and deletion, breach notification in 72 hours, fines up to 4% of turnover.
Data minimization
Collecting and keeping only the data the job needs — the GDPR principle that is also the cheapest security control: what you do not hold cannot leak.
3-2-1 backup rule
Three copies of your data, on two different media, one of them off-site — the floor under every 'we have backups' claim.
Blockchain · 17 terms
Smart contract
A program deployed to a blockchain that runs exactly as written, that anyone can call, and that usually cannot be changed afterwards.
Solidity
The main language for writing smart contracts on Ethereum and the other chains that run the same virtual machine.
Gas
The unit of computational cost on Ethereum-style chains: every operation has a price, and the caller pays it.
ERC-721
The Ethereum standard for non-fungible tokens: a contract interface where every token has its own distinct identity and owner.
Smart contract audit
An independent review of contract code before it goes live, looking for the ways it can be drained, locked or manipulated.
Solana
A high-throughput, low-fee blockchain — thousands of transactions a second at fractions of a cent — built for applications that need speed.
Anchor
The Rust framework for Solana programs — generates the boilerplate and enforces the checks raw Solana development makes easy to forget.
PDA
Program-derived address — a Solana account whose address is computed from seeds, owned by a program, with no private key to steal.
SPL token
Solana's token standard — the shared program every fungible and non-fungible token on the chain uses, so wallets and apps speak one format.
Crypto wallet
The thing that holds your keys, not your coins — signs transactions to prove 'it was me' without ever showing the private key.
On-chain
Recorded on the blockchain itself — permanent, public, verifiable by anyone — as opposed to off-chain data in someone's database.
RPC node
The server your app talks to instead of the blockchain directly — reads chain state and submits transactions; its reliability is your app's reliability.
DeFi
Decentralized finance — lending, trading and yield run by smart contracts instead of institutions, open to anyone with a wallet.
Consensus mechanism
How a blockchain's nodes agree on which transactions happened and in what order — proof of work, proof of stake, and their variants.
MEV
Maximal extractable value — profit from reordering, inserting or censoring transactions in a block; the invisible tax on unprotected swaps.
ERC-20
The fungible-token standard on Ethereum — the interface (transfer, balanceOf, approve) that makes any token work with any wallet or exchange.
Merkle proof
A compact cryptographic proof that one item belongs to a big set — verify a leaf against the root hash without holding the whole tree.
Web and delivery · 60 terms
Core Web Vitals
Google's three field metrics for loading, responsiveness and visual stability, measured on real visits rather than in a lab.
LCP (Largest Contentful Paint)
The moment the biggest piece of content in the viewport finishes rendering — in practice, when the page looks loaded.
Hydration
The step where JavaScript takes over server-rendered HTML in the browser and makes it interactive.
Static generation (SSG)
Rendering pages to HTML at build time, so a request is answered by handing over a file instead of running code.
CI/CD
Automatically building and testing every change, and automatically shipping the ones that pass.
Structured data
Machine-readable markup — usually JSON-LD written in the schema.org vocabulary — that tells search and answer engines what the entities on a page are.
Answer engine optimization (AEO)
Structuring content so that answer engines — chat assistants and AI overviews — can find it, quote it and attribute it correctly.
WCAG
The Web Content Accessibility Guidelines — the standard that defines what makes web content usable by people with disabilities; AA contrast is 4.5:1 for body text.
Idempotency
The property that performing an operation twice produces the same result as once — the thing that makes retries safe in payment, order and automation systems.
Webhook
A URL one system calls to tell another that something happened — the mechanism that lets automations react in seconds instead of polling.
Server-side rendering (SSR)
Generating the page's HTML on the server per request — the browser gets a complete page, not a loader and a promise.
Client-side rendering (CSR)
Sending a JavaScript bundle that builds the page in the browser — flexible, but the first paint waits for the code to download and run.
CDN
Content delivery network — copies of your assets on servers near your visitors, so 'far away' stops meaning 'slow'.
Edge computing
Running code on the CDN's edge servers — close to the user — instead of one origin far away; personalization without the round trip.
HTTP caching
Headers that tell browsers and CDNs how long a response may be reused — the cheapest performance optimization that exists.
DNS
Domain Name System — the lookup that turns dfieldsolutions.com into a server address; when it breaks, everything looks broken.
Canonical URL
A tag naming the one 'real' address for content reachable at several URLs — so search engines rank the copy you meant, once.
hreflang
Annotations that tell search engines which language and region each version of a page targets — so the Hungarian searcher gets the Hungarian page.
XML sitemap
A machine-readable list of every URL worth indexing — last-modified dates included — so crawlers find all of it, fast.
robots.txt
A plain-text file at the site root telling crawlers what they may fetch — an instruction to machines, not a lock on a door.
Open Graph
The meta tags that control how a link looks when shared — the title, description and image in every Slack, WhatsApp and social preview.
llms.txt
A proposed convention — a markdown file at the site root giving AI assistants a clean map of the content worth reading.
Local SEO
Being found when people near you search — the map pack, 'near me' queries, and the Google Business Profile that drives most of it.
NAP consistency
Name, address, phone — written identically everywhere your business appears, because conflicting details make search engines trust none of them.
Google Business Profile
The free listing that puts a business on Google Maps and the local pack — categories, hours, photos and the reviews that decide local trust.
Indexing
A search engine adding a page to its searchable database — crawling fetches it, indexing makes it findable; unindexed is invisible.
301 redirect
A permanent 'it moved' answer — sends visitors and nearly all ranking credit from the old URL to the new one.
ARIA
Accessible Rich Internet Applications — attributes that tell assistive technology what your markup means when HTML alone cannot.
Semantic HTML
Using elements that mean what they contain — nav, article, button — so screen readers, crawlers and browsers understand the page for free.
PWA
Progressive web app — a website that installs like an app: home-screen icon, offline behavior, push, all from the same URL.
Service worker
A script the browser runs between your page and the network — intercepts requests to cache, serve offline and sync in the background.
Design system
The shared vocabulary of a product's UI — tokens, components and rules — so every new screen looks like the same product built it.
Internationalization (i18n)
Building a product so it can be localized — text, dates, URLs and layouts — rather than retrofitting languages into an English-only shell.
SEO
Search engine optimization — making pages findable, indexable and worth ranking: technical health plus content people actually want.
Conversion rate optimization (CRO)
Raising the share of visitors who do the thing — buy, book, enquire — by fixing friction, not by buying more traffic.
Uptime monitoring
An outside service pinging your site every minute and alerting when it stops answering — so you hear about the outage before your customers do.
SERP
Search Engine Results Page — the page Google shows for a query, now a mix of blue links, AI overviews, map packs, and ads.
E-E-A-T
Experience, Expertise, Authoritativeness, Trustworthiness — the quality lens Google's human raters apply, with Trust weighted heaviest.
Backlink
A link from another site to yours — still the strongest external ranking signal, valued by quality and relevance, not count.
Keyword research
Finding out which words people actually type when they need what you sell — the input to every content decision.
Title tag
The HTML title — the blue headline in search results and the strongest single on-page relevance signal.
Meta description
The page summary shown under the title in results — no direct ranking weight, but it writes your ad copy.
Search intent
What the searcher actually wants from a query — to learn, to go somewhere, to compare, or to buy. The thing the page must match.
Featured snippet
The boxed answer Google lifts to the top of results — 'position zero' — pulled from a page that already ranks and answers cleanly.
Knowledge Graph
Google's database of real-world entities and their relationships — what lets it answer 'who founded X' without quoting a page.
Topical authority
Being the site that covers a subject completely — many well-linked pages on one topic beat one page on many topics.
Internal linking
Links between your own pages — how authority flows to the pages that need it and how crawlers and readers find depth.
Anchor text
The clickable words of a link — a description of the destination that search engines read as a relevance vote.
Organic traffic
Visitors who arrive from unpaid search results — the compounding channel that keeps working after the work is done.
Domain authority
The accumulated trust a whole site carries — Google's own version is invisible; the public metrics are third-party approximations.
Crawl budget
How much of your site Googlebot is willing to fetch — only a constraint on large sites, but a real one there.
Mobile-first indexing
Google indexes the mobile version of a site, not the desktop one — whatever the mobile page lacks does not exist for ranking.
Lighthouse
Google's open-source audit tool — scores performance, accessibility, best practices and SEO in a lab environment.
Alt text
The text alternative on an image — what screen readers announce and what image search indexes.
INP
Interaction to Next Paint — the Core Web Vital that measures how fast a page responds to taps and clicks, replacing FID since 2024.
CLS
Cumulative Layout Shift — the Core Web Vital measuring how much the page jumps around while loading.
MVP
Minimum Viable Product — the smallest version that tests the real hypothesis, not a cheap version of the whole thing.
Retainer
An ongoing engagement — a reserved slice of engineering capacity per month instead of one-off projects.
Discovery call
The first conversation before any proposal — where scope, budget reality and fit get established instead of guessed.
Social proof
Evidence that others already trusted you — reviews, named clients, numbers — the shortest path past a stranger's scepticism.
Want this looked at on your own system?Start a conversation
