Threat research, practical guides, and lessons from deploying the control plane in real enterprises.
Memory poisoning makes prompt injection persist for weeks — detonating long after the chat ends. Why classifiers don’t hold, and the controls that bound the damage.
The difference between a log you trust and a receipt anyone can verify, and why it matters in a review.
A practical model for least-privilege authority when your agents can move money and data.
One primitive, found and fixed across Bing Chat, ChatGPT, Claude and Copilot since 2023. Why each fix only partly held.
Map surfaces, not products. Plus the 2023-to-2025 renumbering trap that quietly invalidates most existing maps.
A vendor-neutral protocol: baseline on your own traffic, the four numbers that matter, and an adaptive phase.
We send one substantial piece of AI-security research a month. No noise.