← All posts

AI Security Solutions

97 posts on ai security solutions.

AI Security Posture Management (AI-SPM): What It Covers and Where Runtime Enforcement Fits

AI security posture management (AI-SPM) inventories where AI runs, scores how each deployment is configured, and tracks the data those deployments reach. This guide covers the four capability areas of AI-SPM, where its point-in-time visibility ends, and why the per-request decision and per-decision audit record belong to a runtime enforcement layer at the AI request boundary.

ai-securityai-governancearchitecturepolicy-enforcementcloud-security
Read post →

AI DLP vs Traditional DLP: Why the LLM Request Path Needs a Different Control

Traditional DLP classifies documents and watches known egress channels like email, USB, and web uploads. AI DLP inspects the content of a prompt or response on the LLM request path. This comparison walks the three structural differences, identity correlation, data classification, and enforcement location, and shows why the AI request boundary is where prompt-level policy has to run.

data-loss-preventiondlpai-securityshadow-aipolicy-enforcement
Read post →

AI Agent Guardrails: Constraining a Loop That Chooses Its Own Next Call

Guardrails written for a single chat completion assume one request, one response, one human reading the output. An agent runs a loop: it calls a model, reads the result, picks a tool, calls the model again, and repeats without a human between the steps. That changes what a guardrail has to constrain. This covers the four controls an agent loop needs, why per-call classification is not enough, and how identity-bound authorization limits blast radius when an injected instruction succeeds.

ai-agent-securityai-guardrailsagentic-aiidentity-and-authorizationpolicy-enforcementai-security
Read post →

AI Security Policy: The Eleven Clauses That Have to Be Enforceable

An AI security policy fails at the same place every time: it states what employees and services may send to a model, and nothing in the environment can observe whether that happened. This walks eleven clauses a working policy needs, marks which of them are enforceable at the AI request layer versus which stay administrative, and gives the evidence question to ask of every clause before it ships.

ai-securityai-governancepolicy-enforcementcomplianceshadow-aiaudit
Read post →

AI Guardrails: The Four Layers, What Each One Enforces, and Where the Evidence Comes From

AI guardrails get used as one word for four different control layers: training-time alignment inside the model, provider safety filters at the inference endpoint, application-side validation in the prompt template, and policy enforcement on the HTTP call itself. Each layer sits at a different point in the request path, fails in a different way, and produces a different quality of evidence. This walks all four, shows where each one breaks, and explains which layer an auditor can actually inspect.

ai-guardrailsai-securitypolicy-enforcementai-governancellm-securityaudit
Read post →

LLM Data Security: Five Places Enterprise Data Moves and Which Ones You Can Control

Enterprise data reaches a model through five distinct paths: a user pasting into a prompt, an application assembling context programmatically, a retrieval system injecting documents, a tool call returning results mid-loop, and training or fine-tuning. Each path has a different owner and a different control point. This walks all five, marks which are governable at the HTTP request layer, and explains why prompt-time classification is the one that cannot be substituted.

ai-dlpllm-securityai-securityshadow-aipolicy-enforcementdata-protection
Read post →

Windsurf DLP: The AI Request Paths That Move Source Code

Windsurf DLP is an AI traffic problem with several source-code egress paths: indexed repositories, inline suggestions, chat context, and agent actions. Each path can carry code, fixtures, configuration, or terminal output to an LLM endpoint. This article separates those paths, defines the policy decisions a deployment needs, and locates DeepInspect at the HTTP boundary while naming the endpoint, repository, and credential controls that remain adjacent.

ai-securityllm-securitydata-loss-preventiondlpdevsecopsinline-enforcement
Read post →

Snowflake Cortex DLP Needs Policy at the AI Request Boundary

Snowflake Cortex can carry enterprise context into an LLM workflow. DLP needs a decision point that evaluates the prompt, response, originating identity, data classification, and selected route before content reaches the model. This article sets out the request-path evidence a security review should require.

data-loss-preventiondlpai-securitypolicy-enforcementinline-enforcement
Read post →

SAP Joule DLP Needs Policy at the AI Request Boundary

SAP Joule can carry enterprise context into an LLM workflow. DLP needs a decision point that evaluates the prompt, response, originating identity, data classification, and selected route before content reaches the model. This article sets out the request-path evidence a security review should require.

data-loss-preventiondlpai-securitypolicy-enforcementinline-enforcement
Read post →

Salesforce Einstein DLP Needs Request-Level Policy

Salesforce Einstein can carry enterprise context into an LLM workflow. DLP needs a decision point that evaluates the prompt, response, originating identity, data classification, and selected route before content reaches the model. This article sets out the request-path evidence a security review should require.

data-loss-preventiondlpai-securitypolicy-enforcementinline-enforcement
Read post →

Replit Agent DLP Needs Policy at the AI Request Boundary

Replit Agent can carry enterprise context into an LLM workflow. DLP needs a decision point that evaluates the prompt, response, originating identity, data classification, and selected route before content reaches the model. This article sets out the request-path evidence a security review should require.

data-loss-preventiondlpai-securitypolicy-enforcementinline-enforcement
Read post →

Perplexity Enterprise DLP Needs Request-Level Policy

Perplexity Enterprise can carry enterprise context into an LLM workflow. DLP needs a decision point that evaluates the prompt, response, originating identity, data classification, and selected route before content reaches the model. This article sets out the request-path evidence a security review should require.

data-loss-preventiondlpai-securitypolicy-enforcementinline-enforcement
Read post →