Safeguard
Tag

ai-security

Safeguard articles tagged "ai-security" — guides, analysis, and best practices for software supply chain and application security.

593 articles

AI Security

Transitive Dependency Fix Cascades, Managed

Fixing a transitive dependency is rarely a single bump. It is a cascade. Here is how to manage those cascades without flooding reviewers or breaking builds.

Mar 29, 20267 min read
AI Security

MCP Protocol Security: What the Model Context Protocol Means for Supply Chains

Anthropic's Model Context Protocol standardizes how AI models interact with external tools. The security implications for software supply chains are significant.

Mar 28, 20266 min read
AI Security

Scaling Across Repos: Griffin AI vs Mythos

Multi-repo security reasoning is a graph problem, not a retrieval problem. How Griffin AI's engine scales where pure-LLM products flatten into guesswork.

Mar 28, 20266 min read
AI Security

MCP Server Lifecycle Management Patterns

Patterns for managing MCP servers through development, staging, rollout, and deprecation — with an eye on the security gaps that appear at each transition.

Mar 28, 20268 min read
AI Security

Engine-Plus-LLM vs Pure-LLM Bug Hunters

The difference between an engine-plus-LLM bug hunter and a pure-LLM one is not a tuning detail. It is a structural divide that determines whether the findings are usable.

Mar 26, 20267 min read
AI Security

Model Substitution Attacks: An Emerging Pattern

An attacker who can swap the model behind an API call can read every prompt and shape every response. The emerging trend in 2026 is model substitution as an attack class with its own techniques and disclosures.

Mar 25, 20267 min read
AI Security

Out-Of-Band Confirmation For Irreversible Tool Calls

Some tool calls cannot be undone. Out-of-band confirmation is the cheapest defense for that small set, and the most expensive thing to skip.

Mar 25, 20267 min read
AI Security

Reachability vs Pure-LLM Vulnerability Scanning In 2026

Pure-LLM vulnerability scanners hit production around 2024. By 2026 their failure modes are documented. Reachability remains the backbone — and the LLM is most useful on top of it.

Mar 25, 20263 min read
AI Security

Training Data Poisoning: Pipeline Defenses

A senior engineer's guide to training data poisoning defenses in 2026, from split-learning detection to provenance attestation and continuous pipeline monitoring.

Mar 25, 20267 min read
AI Security

From Finding To Merged Fix In An Hour

A one-hour cycle from vulnerability finding to merged fix is achievable in 2026, but only with a pipeline designed for it. Here is what that pipeline looks like.

Mar 24, 20268 min read
AI Security

Tool-Call Hijacking: Griffin AI vs Mythos

A hijacked tool call is more consequential than a hijacked response. The defence requires the tool layer to police the model, not the other way around.

Mar 24, 20263 min read
AI Security

AI Accelerators: A Security Guide to the Hardware Running Your Models

AI accelerators are the specialized chips that make model training and inference fast, and they bring their own attack surface: memory leakage, driver stacks, and firmware you did not write. Here is what to secure.

Mar 24, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

ai-security (Page 29) — Safeguard Blog