Checklist · · 18 checks
When to bring in a compliance review
The changes that should pull legal, privacy or compliance into an AI project early, and what to have ready when you do. Not legal advice; a way to ask at the right time.
Topic
In the glossary: Defense in depth, Threat model, what each means and how to say it in a review
Part of Security: all Security entries · the Security lens on the map
Checklist · · 18 checks
The changes that should pull legal, privacy or compliance into an AI project early, and what to have ready when you do. Not legal advice; a way to ask at the right time.
Checklist · · 29 checks
What to check before an assistant, RAG app or agent goes in front of real users. Grouped by area, ticked off locally; progress stays in your browser.
Explainer · · 2 min read
Minimise what enters context, watch the paths data can leave by, and keep the evidence an incident will demand.
Explainer · · 2 min read
Narrow tools, staged writes, sandboxes and a tested kill switch. Containment is built before it is needed.
Explainer · · 2 min read
Injection defence is layered validation and clear authority, not a better-worded system prompt.
Explainer · · 2 min read
Assets, actors, abuse cases, controls, owners, evidence. Six things a team can actually write down before launch.
Deep dive · · 5 min read
Notes from building an MCP gateway. The protocol standardised how agents call tools, then stayed silent about credentials, context budgets and who may call what. That silence gets expensive as the servers multiply.
Explainer · · 2 min read
Why retrieved content must stay data, not become authority over the system.
OWASP · Recommended · The threat list to check any tool-calling agent against before it touches production data.