AI Security

AI security is not model security. The exposure sits in what surrounds the model: the prompt that reaches it, the tools it can invoke, the data that leaves with the response, and the packages underneath all three. These posts examine those failure modes as they appear in production. Related: prompt injection, DLP for AI, and egress control in the Trust Fabric.

Agentforce Governance: How to Secure Salesforce AI Agents
Guides

Agentforce Governance: How to Secure Salesforce AI Agents

LLM data masking is disabled for Agentforce agents, so what an agent can reach decides what it can expose. How to govern Agentforce in seven steps.

Craig Alberino · Oct 6, 2026
CrewAI Security and Governance: How to Run Crews in Production
Guides

CrewAI Security and Governance: How to Run Crews in Production

CrewAI's guardrails and hooks check an agent's work inside the run. How to put the controls that must survive a code change outside it, in seven steps.

Craig Alberino · Oct 6, 2026
OpenAI, Hugging Face, and the Deployment Flag
AI Governance

OpenAI, Hugging Face, and the Deployment Flag

The attacking models ran with cyber refusals reduced for an eval. The responders ran with guardrails at full strength and got refused. The variable that decided who got capability was a deployment flag. OpenAI's fix concedes the missing layer and raises the harder question of who should own it.

Craig Alberino · Jul 22, 2026
The WOPR Brief: your monitoring stack is now an attack surface
WOPR

The WOPR Brief: your monitoring stack is now an attack surface

Craig Alberino · Jun 30, 2026
Two Postures on the Agent Call Path
AI Agents

Two Postures on the Agent Call Path

Two postures. Detect above the path. A control watches behavior and flags what looks wrong. Enforce on the path. A control sits inline, in the request itself. One tells you what happened. The other decides whether it happens.

Craig Alberino · Jun 8, 2026
Mythos, Daybreak, and the System Around the Model
AI Governance

Mythos, Daybreak, and the System Around the Model

A restricted frontier model leaked into a proxy this week before its evaluation finished. It raises the question two cyber systems already posed: is the capability the model, or the system around it? On offense, mostly the system. On defense, that answer is where the moat sits.

Craig Alberino · Jun 7, 2026
The Strategy Behind Open-Sourcing Shield
Open Source

The Strategy Behind Open-Sourcing Shield

Free developer tools as a wedge into enterprise security is a known pattern. Here is why APERION ran it on purpose, and what we expect it to do.

Craig Alberino · May 31, 2026
The 51-Point Gap: Why Enterprise AI Security Doesn't Match Adoption
Enterprise AI

The 51-Point Gap: Why Enterprise AI Security Doesn't Match Adoption

Fifty-five percent of enterprises run agentic AI. Four percent are confident in their security posture. The 51-point gap is the runtime governance market, and the reasons it exists explain why workflow and identity governance alone do not close it.

Craig Alberino · May 15, 2026
Why We Open-Sourced Shield
Smartflow

Why We Open-Sourced Shield

Agents in Cursor and Claude Code run tool calls you never see in a PR. DROP DATABASE in a generated migration. rm -rf in a cleanup script. Shield blocks the destructive operations before they execute, and we open-sourced it under Apache 2.0.

Craig Alberino · May 13, 2026
APERION: AI Sovereignty for Regulated Industries
AI Security

APERION: AI Sovereignty for Regulated Industries

Craig Alberino · Apr 1, 2026
What the LiteLLM Supply Chain Attack Means for Enterprise AI
AI Security

What the LiteLLM Supply Chain Attack Means for Enterprise AI

Craig Alberino · Apr 1, 2026
What Is an AI Firewall? Enterprise Guide to AI Security [2026]
Guides

What Is an AI Firewall? Enterprise Guide to AI Security [2026]

What an AI firewall is, how it differs from a WAF, and how to deploy one in front of enterprise LLM applications in seven steps. OWASP LLM Top 10 2026 coverage and on-premises deployment.

Craig Alberino · Mar 2, 2026