Agentic AI/4 min read
AI-agent risk is not just prompt injection. Once an agent can call tools, touch data, modify workflows, or influence CI/CD, it becomes part of the production...
AI Agent Security/10 min read
A pre-launch review list for AI agents that touch production APIs, customer data, tools, memory, or RAG context.
MCP Security/11 min read
A security checklist for MCP servers, clients, OAuth flows, tokens, tools, permissions, trust boundaries, logging, and blast radius.
AI Agent Security/10 min read
AI agent blast radius is the maximum plausible damage an agent can cause if manipulated, misconfigured, over-permissioned, or exposed to hostile context.
RAG Security/9 min read
How to review RAG systems for authorization failures, tenant-isolation gaps, prompt injection, vector-store leakage, document poisoning, and audit logging.
Security Diligence/8 min read
How founders, CTOs, CISOs, and product-security teams can choose between an AI red team, LLM pentest, AI security assessment, or production readiness review.
Security Diligence/9 min read
How engineering and product teams can prepare AI agents for enterprise security review, production launch, customer diligence, and governance scrutiny.
MCP Security/9 min read
An MCP threat model for teams connecting LLMs and AI agents to tools, OAuth tokens, APIs, local servers, SaaS systems, and production workflows.
Prompt Injection/8 min read
How indirect prompt injection reaches AI agents through RAG systems, copilots, MCP tools, webpages, emails, PDFs, memory, and tool outputs.
AI Agent Security/9 min read
A framework for classifying AI agent tool permissions by business impact, authorization boundary, required controls, and production readiness.
RAG Security/8 min read
Common RAG authorization failures, tenant-isolation gaps, vector-store access-control mistakes, source attribution issues, and safer retrieval design.
Post-Incident Engineering/6 min read
How disciplined engineering assessment helps legal, insurance, and executive teams understand root cause, technical exposure, and the next defensible decision...