← All posts

Platform & Architecture

229 posts on platform & architecture.

OpenAI API Gateway Setup: Route SDK Calls Through Policy

Route an existing OpenAI SDK through an API gateway using base_url, then verify caller identity, inspect the request, apply policy and retain the decision record. Includes the request path, endpoint coverage and failure handling.

openaiai-gatewayimplementation-guideenterprise-aiai-securityapi-proxy
Read post →

OpenAI Agent Builder Security: Prompt Injection and Tool Approval

OpenAI Agent Builder security starts with prompt injection, structured outputs, and approval for MCP operations. This guide maps those workflow controls to the model-request authorization record enterprises need for each routed HTTP call.

ai-securityagentic-aiprompt-injectionidentity-and-authorizationinline-enforcementllm-security
Read post →

OWASP AISVS 1.0: A Gateway Control Mapping

OWASP AISVS 1.0 contains 514 verification requirements across identity, prompt handling, response filtering, MCP, audit, model, supply-chain, and governance work. This gateway mapping separates request-path evidence from controls owned by other teams.

ai-securityowaspverificationpolicy-enforcementauditarchitecture
Read post →

Claude Enterprise Security: SSO, SCIM, Audit Logs

Anthropic's Claude Enterprise ships SAML SSO, SCIM provisioning, a no-training default, and an audit log surface, the controls buyers search for by name. This piece names each one, marks where it stops at the account boundary, and gives the identity-aware authorization pattern that closes the request-level gap on Claude traffic, with API-call detail for engineers.

ai-securityllm-securityidentity-and-authorizationinline-enforcementarchitecturepolicy-enforcementaudit
Read post →

LLM Proxy vs API Gateway: Why a Generic Gateway Cannot See Model Traffic

A generic API gateway routes requests, checks a key, and counts calls, which is why teams reach for one in front of their LLM traffic. It stops short of the decisions AI traffic needs: who the caller is at a user grain, what the prompt contains, and a record of the AI decision. This piece compares the two on what each can see and enforce, and where the boundary between them sits.

ai-gateway'llm-proxy''api-gateway''ai-security''architecture'
Read post →

LiteLLM vs an AI Security Gateway: What Each One Does and Where They Compose

LiteLLM is an open-source LLM proxy that normalizes the API surface across more than 100 model providers and handles routing, retries, fallbacks, cost tracking, and basic key management. An AI security gateway sits at the same network position but answers a different question: identity-bound policy on prompt content, data classification at the request boundary, and a per-decision audit record that holds up under EU AI Act Article 12 review. The two products compose in production deployments. This piece walks through what each one does, where they overlap, and where the architectural responsibilities split.

litellmai-gatewaycomparisoninline-enforcementai-architectureaudit
Read post →

AI Security Proxy: What the Pattern Is and How It Differs from Traditional Web Proxies

An AI security proxy intercepts HTTP traffic between authenticated users or agents and LLM APIs, evaluates each request against identity-bound policy, and writes a per-decision audit record before the response returns. The pattern differs from the traditional forward proxy at four architectural points: prompt-level data classification, identity binding at the request layer, fail-closed policy evaluation, and tamper-evident audit independence. I walk through the architecture and where it fits in the 2026 enterprise AI stack.

ai-securityai-gatewayenforcementarchitectureauditai-proxy
Read post →

AI Gateway Latency Benchmarks: Reading the 2026 Numbers Without Getting Fooled by the Mock Upstream

AI gateway latency benchmarks in 2026 report figures from microseconds to tens of milliseconds, but almost all of them measure proxy forwarding against a mock upstream, which deletes the largest real-world variable. This article defines the metrics that matter, reads the LiteLLM, Bifrost, Kong, and Portkey numbers with their methodology caveats, and shows why gateway overhead is a small fraction of provider TTFT and how to keep policy evaluation off the critical path.

ai-gatewayarchitectureinline-enforcementai-securityllmpolicy-enforcement
Read post →

Gong AI Security: SOC 2, ISO 42001, and Retention

Gong holds SOC 2 Type II certification and ISO/IEC 42001:2023 certification for AI management, states that customer conversation data is never used to train its generative models, and lets each customer configure retention themselves. This covers what Gong's Trust Center answers and what it does not: which authenticated identity triggered a specific AI request, what conversation content it carried, and whether a policy decision on that request is provable independent of Gong's own systems.

ai-securityllm-securityauditpolicy-enforcementidentity-and-authorizationarchitecture
Read post →

Dropbox Dash Audit Logs: Evidence for Search Answers

Dropbox Dash audit logs need to answer a narrower and harder question than who opened a file: what source material was assembled for an AI answer, which authenticated person requested it, and which policy was in force. This article separates Dash and source-system evidence from the HTTP model-call record needed to reconstruct an answer.

auditforensic-auditai-securityllm-securityidentity-and-authorizationarchitecture
Read post →

Zoom AI Companion Security: Separate Content, Models, and Controls

Zoom AI Companion security depends on the content source and function in use. The model deployment, administrator setting, and retention configuration also matter. A useful review traces meeting transcripts and chat messages separately from connected-source content and task execution. It also distinguishes Zoom-managed AI processing from any customer-controlled HTTP model route where an independent request-policy decision could operate.

ai-securityllm-securityidentity-and-authorizationpolicy-enforcementcloud-security
Read post →

Windsurf Security: Six Devin Desktop Boundaries to Review

Windsurf security now needs current Cognition terminology. Devin Desktop provides native controls for SSO, SCIM, RBAC, model availability, terminal execution, MCP access, deployment, and sharing. Cognition separately documents encryption and customer-data practices. These preventive controls need distinct owners, and only configurable AI HTTP traffic can pass through an independent request-policy gateway.

ai-securityagentic-aiidentity-and-authorizationzero-trustcloud-security
Read post →