← All posts

Platform & Architecture

229 posts on platform & architecture.

Cursor Audit Logs and AI Request Evidence

Cursor teams need evidence that connects each AI request to an authenticated actor, policy decision, and timestamp. This article separates provider administration records from independent request-layer evidence and maps the HTTP controls that regulated enterprises can verify during a security review.

ai-securityllm-securityauditinline-enforcementpolicy-enforcement
Read post →

CrewAI Audit Logs and Per-Request Evidence

CrewAI teams need evidence that connects each AI request to an authenticated actor, policy decision, and timestamp. This article separates provider administration records from independent request-layer evidence and maps the HTTP controls that regulated enterprises can verify during a security review.

ai-securityllm-securityauditinline-enforcementpolicy-enforcement
Read post →

Cohere Security for Enterprise AI Traffic

Cohere teams need evidence that connects each AI request to an authenticated actor, policy decision, and timestamp. This article separates provider administration records from independent request-layer evidence and maps the HTTP controls that regulated enterprises can verify during a security review.

ai-securityllm-securityauditinline-enforcementpolicy-enforcement
Read post →

Cohere Audit Logs for Enterprise AI Requests

Cohere teams need evidence that connects each AI request to an authenticated actor, policy decision, and timestamp. This article separates provider administration records from independent request-layer evidence and maps the HTTP controls that regulated enterprises can verify during a security review.

ai-securityllm-securityauditinline-enforcementpolicy-enforcement
Read post →

Canva AI Security and Prompt-Level Data Controls

Canva AI teams need evidence that connects each AI request to an authenticated actor, policy decision, and timestamp. This article separates provider administration records from independent request-layer evidence and maps the HTTP controls that regulated enterprises can verify during a security review.

ai-securityllm-securityauditinline-enforcementpolicy-enforcement
Read post →

Amazon Q Audit Logs at the AI Request Boundary

Amazon Q teams need evidence that connects each AI request to an authenticated actor, policy decision, and timestamp. This article separates provider administration records from independent request-layer evidence and maps the HTTP controls that regulated enterprises can verify during a security review.

ai-securityllm-securityauditinline-enforcementpolicy-enforcement
Read post →

Box AI Security: What the New Agent Controls Cover, and What They Do Not

Box announced prompt injection detection and MCP guardrails for AI agents on July 22, 2026, plus audit trails covering more than 300 admin actions. The controls secure what happens inside Box and what external agents may do to Box content. They do not evaluate outbound calls an application makes from Box data to an external LLM API.

ai-securityauditforensic-auditllm-securityagentic-aiarchitecture
Read post →

Azure AI Foundry Security: What Entra ID, Private Endpoints, and RBAC Cover

Microsoft Entra ID, private endpoints, and RBAC secure three separate layers of an Azure AI Foundry deployment: authentication, network isolation, and resource-management permissions. None of the three evaluates whether a specific authenticated end user should be allowed to send a specific prompt to a specific model right now.

ai-securitycloud-securityllm-securityidentity-and-authorizationarchitecturezero-trust
Read post →

Azure AI Foundry Audit Logs: What Tracing and Monitoring Actually Record

Azure AI Foundry traces LLM calls, tool invocations, and agent decisions through OpenTelemetry integrated with Azure Monitor Application Insights. The tracing captures the Entra ID identity or managed identity making the call, not necessarily the end user a multi-tenant application serves. This piece maps what Foundry observability records and where the identity gap sits.

ai-securityauditforensic-auditllm-securitycompliancearchitecture
Read post →

Atlassian Intelligence Security: Evidence for AI Actions in SaaS

Atlassian Intelligence operates inside Atlassian cloud products and acts on the content and permissions available in those products. A sound security review maps the identity, data, feature, audit, and connector boundaries for the selected use case. This article distinguishes SaaS application controls from direct LLM API request policy.

ai-securityagentic-aiauditidentity-and-authorizationpolicy-enforcementzero-trust
Read post →

AWS Bedrock Security: What Guardrails, PrivateLink, and IAM Do Not Cover

Bedrock Guardrails, PrivateLink, and IAM resource policies cover three real but separate security jobs: content filtering, network isolation, and API authorization. None of the three evaluates whether a specific authenticated caller should be allowed to send a specific prompt right now. This piece maps the three controls and the request-authorization gap between them.

ai-securitycloud-securityllm-securityidentity-and-authorizationarchitecturezero-trust
Read post →

AWS Bedrock Audit Logs: What Model Invocation Logging Actually Captures

Amazon Bedrock model invocation logging records the full request and response body plus the IAM ARN of the calling principal, but it is disabled by default and the identity field it captures is a role, not a person. This piece breaks down the log schema, the CloudTrail split, and what an auditor still cannot get from either.

ai-securityauditforensic-auditllm-securitycompliancearchitecture
Read post →