Articles
Browse every published technical guide on Architecting Secure AI. Articles are grouped by subject so readers and search engines can reach the complete archive without relying on thin label or search-result pages.
The collection focuses on practical AI security architecture, production LLM systems, retrieval security, MCP governance, and cloud-native infrastructure. Each topic path combines implementation guidance, security boundaries, and primary references so you can move from fundamentals to deployment decisions.
Agentic AI architecture, governance, and security
Start here for agent design, identity, authorization, human approval, enterprise integration, threat modeling, and governance. The ten-part architecture series provides a structured path, while DVAIB and the jailbreak guides add hands-on security examples.
- Introducing DVAIB - Damn Vulnerable AI Bank
- Multi-Turn Jailbreaks and Psychological Manipulation Attacks: Why Single-Turn Defenses Fail
- Policy-as-Code for AI Workloads in Kubernetes: Kyverno/OPA Patterns for Model and Data Safety
- Securing Agentic AI Part 1: Architecture, Patterns, and Governance
- Securing Agentic AI Part 2: Agent Architecture Patterns and Security Analysis
- Multi-Agent AI Security: Trust Boundaries and Handoffs (Part 3)
- Securing Agentic AI Part 4: Human-in-the-Loop Design Patterns
- Securing Agentic AI Part 5: Threat Landscape for Agentic Systems
- Securing Agentic AI Part 6: Identity and Access Control for Agents
- Securing Agentic AI Part 7: Secure Architecture Patterns
- Securing Agentic AI Part 8: Enterprise Integration
- Securing Agentic AI Part 9: Governance Framework
- Securing Agentic AI Part 10: Implementation Roadmap
- Agentic AI: Using a Buzzword to Justify Premium Charges
- Graceful Degradation Strategies for GenAI Systems
- Beyond Static Threats: Temporal Vulnerability Amplification in ML Security
RAG, embeddings, and vector security
These guides explain retrieval and embedding foundations before moving into vector injection, database security, application-aware retrieval, and privacy-preserving RAG. Use this path when designing systems that store, search, or protect semantic data.
- Building Privacy-Preserving RAG with Homomorphic Encryption
- AI's Dirty Secret: Embeddings Are Just Unsalted Hashes Waiting to Be Cracked
- RAG+ Revolution: How Application-Aware Reasoning Transforms AI Knowledge Systems
- Top 10 Security Issues for Vector Databases and AI Systems
- Evolving Database Security: From SQL Injection to Vector Database Vulnerabilities
- Understanding Vector Search: A Comprehensive Guide
- Building Faster Vector Databases with HNSW
- Understanding Vector Embeddings: A Beginner's Guide
LLM inference and model architecture
This path covers transformer fundamentals, mixture-of-experts routing, numeric precision, production inference servers, and KV-cache security. It connects model internals to latency, throughput, memory isolation, and multi-tenant deployment choices.
- Long-Context Inference Security: KV-Cache Privacy Risks and Safe Memory Management
- Decoding FP32, FP16, FP8, INT8, and INT4
- Mixture of Experts: The Specialist Consultant Revolution
- How Transformers Actually Work: The Complete Simple Guide
- Complete Guide to LLM Inference Servers: From Basics to Production
- The Complete Guide to Transformer Architecture
MCP and secure AI development tools
Use these guides to design governed MCP control planes and secure AI-assisted development environments. The focus is identity, policy enforcement, validation, auditing, rate limits, observability, and enterprise endpoint controls.
- Enterprise MCP Security Architecture: A Production Guide
- Securing Claude Code for macOS in Enterprise Environments
- Securing Claude Code for Windows Enterprise Deployments
Containers, Kubernetes, and infrastructure
This path builds from Linux isolation and container images through runtimes, networking, Kubernetes secrets, software supply-chain evidence, and direct high-speed AI infrastructure. The articles emphasize reproducible configuration and the operational boundaries behind each abstraction.
- Ways to Secure Secrets on Kubernetes and OpenShift
- Container Receipts and Container SBOMs
- Container Networking: The Invisible Connections of DigiLand
- Container Images: Building the Blueprints of DigiLand
- Container Runtime Architecture: The Engine Room of DigiLand
- Linux Fundamentals Behind Containers
- Containers vs. Virtual Machines
- One Cable, 200 Gbit/s: Connecting Two GB10 Systems with ConnectX-7
Last reviewed: August 2026