← All posts

Platform & Architecture

229 posts on platform & architecture.

What Is an AI Control Plane? Control Plane vs Data Plane for AI Traffic

An AI control plane is the layer that decides policy, identity, routing, and audit for AI requests, kept separate from the data plane that carries the actual prompt and completion. This explainer borrows the control-plane and data-plane split from networking, applies it to LLM traffic, names the four components, and shows why separating the two produces deterministic policy and an independent audit record.

architectureai-securitypolicy-enforcementllmzero-trust
Read post →

Google Agentspace Security: The Enterprise Answer Boundary

Google Agentspace security requires an access review that follows enterprise retrieval context into the model route used for an answer. This article separates source and identity administration from the HTTP request boundary where policy can inspect model egress and create independent decision evidence.

ai-securityllm-securityzero-trustpolicy-enforcementidentity-and-authorizationarchitecture
Read post →

Google Agentspace Audit Logs: Evidence for Agent Answers

Google Agentspace audit logs should join the originating employee or agent, retrieved enterprise sources, model route, and authorization decision for one answer. This article maps provider and source events to the independent HTTP request record needed to reconstruct model egress during a security review.

auditforensic-auditllm-securitypolicy-enforcementidentity-and-authorizationarchitecture
Read post →

Glean Audit Logs: Reconstructing an Enterprise AI Answer

Glean audit logs need to join the person who asked, the retrieved enterprise sources, the model route, and the policy decision that governed egress. This article separates source and administration events from a per-decision HTTP record that can reconstruct one AI answer during a security review.

auditforensic-auditllm-securitypolicy-enforcementidentity-and-authorizationarchitecture
Read post →

Figma AI Security: A Design Context Egress Review

Figma AI security requires a concrete review of what design context can be included in a request, which workspace identity initiated it, and what provider route processes it. This article separates Figma workspace administration from the HTTP model-call decision where external policy enforcement and independent evidence can operate.

ai-securityllm-securityai-governancezero-trustpolicy-enforcementaudit
Read post →

Dropbox Dash Security: The Retrieval Permission Review

Dropbox Dash security depends on the permission state of the connected content it retrieves, the identity attached to a request, and the route that carries assembled context to a model. This technical review maps those layers and identifies the HTTP AI decision that an external enforcement layer can inspect.

ai-securityllm-securityzero-trustpolicy-enforcementidentity-and-authorizationarchitecture
Read post →

DeepSeek Audit Logs: Evidence for Every Routed Model Request

DeepSeek audit logs become useful evidence when they bind an authenticated caller, model route, policy version, prompt classification, and permit or deny outcome to each HTTP request. This article separates provider records from the independent, per-decision evidence a security review needs.

auditforensic-auditllm-securitypolicy-enforcementidentity-and-authorizationarchitecture
Read post →

Amazon Q Security at the AI Request Boundary

Amazon Q teams need evidence that connects each AI request to an authenticated actor, policy decision, and timestamp. This article separates provider administration records from independent request-layer evidence and maps the HTTP controls that regulated enterprises can verify during a security review.

ai-securityllm-securityauditinline-enforcementpolicy-enforcement
Read post →

DeepSeek Security at the AI Request Boundary

DeepSeek security depends on controls at several layers. The request boundary needs authenticated identity, delegated authority, prompt classification, route policy, and decision evidence. Provider configuration, local execution, and credential security remain adjacent responsibilities with different owners.

ai-securityllm-securityzero-trustpolicy-enforcementidentity-and-authorizationarchitecture
Read post →

Databricks Mosaic AI Security at the HTTP Request Boundary

Databricks Mosaic AI security begins with Unity Catalog permissions and governed AI services, then needs a clear decision point for each HTTP request and response an application sends to an LLM. This article maps the security review to identity context, model routes, policy evaluation, and evidence at the request boundary without overstating proxy coverage.

ai-securityllm-securityzero-trustinline-enforcementpolicy-enforcementidentity-and-authorization
Read post →

Databricks Mosaic AI Audit Logs at the Request Boundary

Databricks Mosaic AI audit logs need to do more than retain prompts and responses. A reviewable record connects an HTTP model request to the originating identity, route, evaluated policy, response outcome, and timestamp. This article separates Databricks-native usage records from independent request-boundary evidence for mixed model deployments.

ai-securityllm-securityauditforensic-auditinline-enforcementpolicy-enforcement
Read post →

Cursor Security at the AI Request Boundary

Cursor security depends on knowing which authenticated actor sent each AI request, which policy applied, and which evidence survives a later review. This article maps provider records, request-layer controls, and the HTTP boundary that regulated enterprise teams can verify.

ai-securityllm-securityauditinline-enforcementpolicy-enforcement
Read post →