Start here

Recommended order

  1. Prompt injection and instruction manipulation
  2. Sensitive data exposure in AI workflows
  3. AI firewalls and runtime guardrails

11 guides

Security team guides

For Security Teams

Prompt injection and instruction manipulation

Learn how prompt injection and instruction manipulation affect AI applications, where indirect attacks appear, and what evidence buyers should request.

What is prompt injection, why does it matter, and what controls can reduce the risk?

For Security Teams

Sensitive data exposure in AI workflows

Learn where sensitive data can leak across prompts, outputs, retrieval, embeddings, logs, SaaS AI tools, and AI application workflows.

Where can sensitive data leak across prompts, outputs, retrieval, embeddings, logs, training, and SaaS AI tools?

For Security Teams

Excessive agency and tool-use risk

Learn how security teams should assess AI agent tool-use risk, permission boundaries, approval gates, logging, and control evidence.

What risks emerge when AI systems can call tools, use permissions, trigger workflows, or act through identities?

For Security Teams

Keep software assurance up with AI coding agents

Learn how security and engineering teams can scale testing, review, release evidence, monitoring, and rollback as AI coding agents increase software change volume.

How can organizations safely absorb software changes at the rate AI coding agents can generate them?

For Security Teams

Data exposure in retrieval and vector search

Learn how retrieval, embeddings, vector search, access control gaps, and source attribution can expose sensitive information in AI applications.

How can retrieval, embeddings, vector search, and access control gaps expose sensitive information?

For Security Teams

AI asset inventory and governance

Learn what security teams should include in an AI asset inventory and how it supports AI governance, risk management, and control assurance.

What should be included in an AI asset inventory and how does it support governance and control assurance?

For Security Teams

Model and data supply chain risk

Learn how security teams should assess risks across models, datasets, pipelines, registries, dependencies, third-party components, and AI deployment workflows.

What can go wrong across models, datasets, pipelines, registries, dependencies, and third-party AI components?

For Security Teams

AI firewalls and runtime guardrails

Learn where runtime AI controls sit, what they inspect, where they cannot see, and what evidence buyers should request.

Where do runtime AI controls sit, what can they inspect, and what proof should buyers ask for?

For Security Teams

AI red teaming and evaluation

Learn what AI red teaming and evaluation should prove before and after deployment, including prompt injection, data exposure, misuse, tool-use risk, and evidence.

What should AI red teaming and evaluation prove before an AI system is trusted in production?

For Security Teams

Logging, monitoring, and evidence generation for AI security

Learn what logs, alerts, reports, and audit evidence help security teams operationalize AI security across AI applications, agents, data flows, and runtime controls.

What logs, alerts, reports, and audit evidence help security teams operationalize AI security?

For Security Teams

Map AI security to OWASP, NIST, CSA, and MITRE

Learn how to translate AI security risks and vendor claims into OWASP, NIST, CSA, MITRE, and internal control language.

How can AI security risks and vendor capabilities be mapped to OWASP LLM Top 10, NIST AI RMF, CSA AI Controls Matrix, MITRE ATLAS, and internal control frameworks?

AI Security Product Landscape

Turn control questions into product evidence.

Use the guides to compare product capabilities, control surfaces, framework coverage, and verification questions.

For Business Leaders