AI Supply Chain Security: Models, Data, Code, and Provenance
An operational AI supply-chain guide covering models, datasets, code, containers, prompts, services, provenance, release controls, and incident response.
Category
Defensive engineering, governance, and risk analysis for AI systems and agents.
An operational AI supply-chain guide covering models, datasets, code, containers, prompts, services, provenance, release controls, and incident response.
A developer-focused architecture guide to LLM trust boundaries, authorization, retrieval, output validation, tool safety, secrets, and monitoring.
An operational matrix connecting AI threats to controls, evidence, response, verification, and ownership.
What system prompts can guide, what they cannot enforce, and how to place them within defense in depth.
A current defensive guide to MCP hosts, clients, servers, tools, resources, trust boundaries, consent, and least privilege.
Implementation guidance for making model-proposed tool calls bounded, validated, authorized, and observable.
What to log and trace so teams can explain AI-agent actions, approvals, tool calls, and side effects.
A practical architecture for containing AI-generated code, shell commands, browser actions, and artifacts.
A repeatable worksheet for threat modeling LLM, agent, RAG, memory, and model-supply-chain boundaries.
A practical trust graph for securing delegation and message boundaries between autonomous agents.
A defensive pipeline for finding and containing data and model poisoning before it changes production behavior.
A practical model-artifact security chain for protecting weights, adapters, checkpoints, and deployment bundles.
A practical guide to preventing context and memory poisoning through controlled writes, provenance, scoped retrieval, expiry, and recovery.
A practical framework for placing meaningful human approval controls around consequential AI-agent actions without causing approval fatigue.
A practical guide to credential brokers, short-lived tokens, secret stores, per-tool isolation, multi-tenant boundaries, safe logging, and incident response.
A practical identity architecture for AI agents: separate user, workload, service, and delegated principals while preserving accountability across every tool call.
A practical method for threat-led AI red teaming, safe test design, model-versus-system evidence, severity, remediation, and regression testing.
An end-to-end RAG security architecture for source governance, retrieval authorization, tenant isolation, poisoned content, safe output, and audit evidence.
A threat-boundary guide to indirect prompt injection through external content, with attack-path analysis, containment architecture, testing, and developer controls.
A practical authorization model for AI agents covering tool policy, scoped credentials, human approval, multi-tenant boundaries, and audit evidence.
A complete engineering guide to AI agent identity, permissions, tools, credentials, data, memory, isolation, approvals, monitoring, and testing.
A threat-model-driven guide to direct and indirect prompt injection, attack paths, impact containment, tool authorization, output validation, testing, and monitoring.