A field guide to AI security for founders and builders shipping fast.
Prompt injection, leaked credentials, rogue automations, and model behavior drift are now product risks. This book gives you practical controls that fit real startup velocity.
The book is being written in public. Read the 13-part series free, or join the waitlist for launch updates, early access, and release pricing.
Founders, lead engineers, and small teams putting LLMs, agents, and RAG into real products. You do not have a security department. You do have customer data, API keys, and a model that will cheerfully follow instructions hidden in a PDF. The starting assumption is in the title: the model, the tool call, or the prompt will fail eventually, so design for the blast radius.
Least privilege for agents, isolating tools and tenants so one prompt cannot reach everything, and locking down MCP servers.
RAG pipelines and vector databases that expose documents, and a proxy that scrubs SSNs, card numbers, and PII before a prompt leaves your network.
Code assistants, MCP devtools, CI bots, AI in the deploy pipeline, and the shadow AI your team installed without asking.
Human review that is more than a rubber stamp, red-teaming your own AI, and logging and incident response for systems that fail probabilistically.
Data minimization for agents under GDPR and the EU AI Act, and how not to become a non-compliant HIPAA data processor by accident.
The book grows out of this 13-part series. Each post stands on its own.
Related: the AI security assessment, and the rest of Seth's books.