Writing

Research and field notes

Deep dives, threat analysis, and notes from the work - mostly on AI and agent security, sometimes on whatever is breaking this week.

Latest

Choosing an AI Agent Memory Service: Security and Performance Tradeoffs

A memory-service decision method with a small local SQLite experiment, tenant checks, deletion limits, and latency measurements.

September 9, 20265 min readAI Systems

Read note

September 9, 20265 min read

How to Evaluate Tools for Securing Production AI Agents

An evaluation method that follows identity, authority, approval, and failure behavior through a real agent workflow.

AI AgentsSecurity ArchitectureEvaluation
September 9, 20265 min read

Tamper-Evident AI Agent Logs: Integrity, Gaps, and Limits

A runnable local log-chain experiment covering edits, deletion, replay, truncation, drops, restarts, and signer compromise.

AI AgentsLoggingIntegrity
September 9, 20264 min read

What AI Agent Assurance Claims Actually Cover

How to read an agent assurance claim through its scope, assessor, test version, and renewal conditions.

AI AgentsAssuranceAccess Control