Blog

Analysis on enterprise AI governance, inline policy enforcement, agentic AI security, and regulatory compliance.

Figma AI Security: A Design Context Egress Review

Figma AI security requires a concrete review of what design context can be included in a request, which workspace identity initiated it, and what provider route processes it. This article separates Figma workspace administration from the HTTP model-call decision where external policy enforcement and independent evidence can operate.

Platform & Architectureai-securityllm-securityai-governancezero-trustpolicy-enforcementaudit
Read post →

Dropbox Dash Audit Logs: Evidence for Search Answers

Dropbox Dash audit logs need to answer a narrower and harder question than who opened a file: what source material was assembled for an AI answer, which authenticated person requested it, and which policy was in force. This article separates Dash and source-system evidence from the HTTP model-call record needed to reconstruct an answer.

Platform & Architectureauditforensic-auditai-securityllm-securityidentity-and-authorizationarchitecture
Read post →

Gong AI Security: Governing Revenue Conversation Context

Gong AI security reviews should trace identity, conversation context, retention, and the route used for model processing. This article separates Gong administration and CRM permissions from the HTTP AI request boundary where identity-aware policy can govern prompt content and preserve a per-decision record.

Platform & Architectureai-securityllm-securityauditpolicy-enforcementidentity-and-authorizationarchitecture
Read post →

Glean Security: An Access and AI Egress Review

Glean security requires a review of connector access, source permissions, user identity, and the model route used for generated answers. This article maps those decisions to the HTTP request boundary where external policy enforcement can inspect egress and create independent decision evidence.

Platform & Architectureai-securityllm-securityzero-trustpolicy-enforcementidentity-and-authorizationarchitecture
Read post →

Dropbox Dash Security: The Retrieval Permission Review

Dropbox Dash security depends on the permission state of the connected content it retrieves, the identity attached to a request, and the route that carries assembled context to a model. This technical review maps those layers and identifies the HTTP AI decision that an external enforcement layer can inspect.

Platform & Architectureai-securityllm-securityzero-trustpolicy-enforcementidentity-and-authorizationarchitecture
Read post →

DeepSeek Audit Logs: Evidence for Every Routed Model Request

DeepSeek audit logs become useful evidence when they bind an authenticated caller, model route, policy version, prompt classification, and permit or deny outcome to each HTTP request. This article separates provider records from the independent, per-decision evidence a security review needs.

Platform & Architectureauditforensic-auditllm-securitypolicy-enforcementidentity-and-authorizationarchitecture
Read post →

Amazon Q Security at the AI Request Boundary

Amazon Q teams need evidence that connects each AI request to an authenticated actor, policy decision, and timestamp. This article separates provider administration records from independent request-layer evidence and maps the HTTP controls that regulated enterprises can verify during a security review.

Platform & Architectureai-securityllm-securityauditinline-enforcementpolicy-enforcement
Read post →

SR 11-7 and Banking AI Model Risk After SR 26-2

SR 11-7 was superseded by SR 26-2 on 17 April 2026. For banks using LLMs and agents, SR 26-2 keeps the model-risk-management disciplines of governance, independent challenge plus monitoring and outcomes analysis while expressly placing generative and agentic AI outside its direct scope. This guide explains the governance decision plus production-review evidence and the limits of request-layer controls.

Industry Verticalsbankingfinancemodel-riskai-compliancemodel-validationaudit-trail
Read post →

AI Agent Sandbox: Isolation Controls for Agent Runtime Risk

An AI agent sandbox confines the local process, file paths, network destinations plus credentials, and temporary state available to an agent runtime. This guide maps isolation choices through OS process controls into microVMs, explains the evidence each boundary produces, and separates runtime containment from policy enforcement on routed LLM requests.

Problem-Awareai-agent-securityagentic-aisandboxruntime-isolationblast-radiusdefense-in-depth
Read post →

Agentic AI Permission Control: Per-Action Delegated Authority

Agentic AI permission control evaluates every model request against the person or workflow that delegated it, the allowed model route, data classification, policy version, and expiry. This framework separates a long-lived agent credential from the short-lived authority needed for one action, then records the permit, redaction, or denial decision for review.

Problem-Awareagentic-aiai-securityidentity-and-authorizationnist-ai-rmfinline-enforcement
Read post →

GitHub Copilot Audit Logs: The Missing Prompt Record

GitHub Copilot audit logs can establish enterprise and policy activity, yet an AI evidence review also needs the request-level record for code context sent to a model. This article separates GitHub administration and repository controls from the HTTP AI call where identity-bound policy and independent decision records can be applied.

Platform & Architectureauditforensic-auditllm-securityai-securitydevsecopsidentity-and-authorization
Read post →

DeepSeek Security at the AI Request Boundary

DeepSeek security depends on controls at several layers. The request boundary needs authenticated identity, delegated authority, prompt classification, route policy, and decision evidence. Provider configuration, local execution, and credential security remain adjacent responsibilities with different owners.

Platform & Architectureai-securityllm-securityzero-trustpolicy-enforcementidentity-and-authorizationarchitecture
Read post →