Writing

Blog

Cryptographic AI audit architecture, regulatory framework deep dives (DORA, EU AI Act), hash-chain evidence pack formats, and integration patterns for regulated enterprise deployments.

New: practical guides on passing the AI section of enterprise security reviews (CSA AI-CAIQ, NIST AI RMF). More on runtime evidence and hash-chain audit architecture landing regularly.
Jul 31, 20269 minGuide

EU AI Act logging requirements for AI deployers: a practical checklist

Article 12 makes providers build logging in. Article 26 makes deployers keep the logs. What the record-keeping obligations actually say, who holds which duty, and a checklist you can hand to engineering.

Read →
Jul 30, 20268 minGuide

Shared service accounts vs per-user credentials for AI agents: the security review question you'll fail

One service account for every agent action is the default architecture, and it is the first thing a reviewer flags. Why attribution breaks, what reviewers ask instead, and the migration path that passes.

Read →
Jul 29, 202610 minGuide

AI agent audit trail requirements: what SOC 2, HIPAA and DORA actually ask for

Three frameworks, three different audit-trail demands. What SOC 2 monitoring criteria, HIPAA 164.312(b), and DORA expect from agent logs, where a normal application log falls short, and what to build.

Read →
Jul 28, 20269 minGuide

The MCP security review: what enterprise buyers ask about Model Context Protocol in 2026

Your agent product speaks MCP, and the buyer's security team has started asking about it by name. The tool-poisoning, credential, and audit questions they raise, and the evidence that closes each one.

Read →
Jul 14, 202616 minPillar

The AI security question bank: every question the AI section asks, with the evidence that satisfies each

21 questions reviewers pull from for the AI section of vendor security reviews, grouped by category. Why they ask, what evidence closes each one, and what to say when you don't have the control yet.

Read →
Jul 14, 202610 minVertical

The AI security review for healthcare AI startups: what hospital and payer reviewers ask

PHI at inference time, embeddings in tenant isolation, EHR write access, BAAs for agent vendors. The questions healthcare AI startups get in security reviews and the evidence that answers them.

Read →
Jul 14, 202610 minVertical

The AI security review for fintech AI startups: what bank and credit-union reviewers ask

Decision traceability, agent credentials, fair-lending overlays, TPRM questionnaires. The questions fintech AI startups get from bank reviewers and the evidence that answers them.

Read →
Jul 10, 20268 minComparison

Your deal is stuck on the AI section. Your five options, honestly compared

DIY, ChatGPT, GRC consultant, questionnaire automation, or a done-for-you kit. Cost, speed, and risk of each way to answer the AI section of an enterprise security questionnaire.

Read →
Jul 9, 202614 minPillar

The 20 AI security review questions enterprises ask vendors, and how to answer each

Enterprise security reviews grew an AI section in 2026. The 20 questions AI vendors actually get, what the reviewer wants behind each one, and how to answer from your real stack.

Read →
Jul 8, 20267 minGuide

What evidence buyers actually accept for your AI answers

A policy says what should happen. Reviewers increasingly want proof of what did. The hierarchy of AI-section evidence, from the answer that stalls a deal to the one that closes it.

Read →
Jul 7, 20269 minGuide

How to answer the AI-CAIQ: a vendor's field guide

The CSA's AI-CAIQ added 320 AI-specific questions to vendor security reviews. What it asks, how it differs from the CAIQ, what evidence buyers accept, and how to answer without stalling your deal.

Read →