Blog

Field notes on AI-native security operations

Practical writing on governed autonomy, reversible response, evidence, and the engineering behind safe automation. Our first posts are on the way.

Coming soon — topics we're writing about
Response

Authority to act: how to automate response without losing control

The authority ladder — observe, approval, pre-authorized, contractual-auto — and why business-critical assets should never auto-run.

Engineering

Reversible by design: undoing a containment action safely

Terminal-state fail-safe attribution, and why a reversal must only ever touch the effect your own run created.

AI

Redaction fences and the zero-config floor

Why an empty AI-egress policy must mean 'redact everything', never 'send everything' — and how we enforce it at the boundary.

Response

Fleet-wide actions deserve a different gate

Breadth is its own risk axis. Why tenant-wide IOC blocks are always approval-first and human-run, independent of reversibility.

Evidence

Evidence you can defend: chain of custody in practice

Hashing on capture, provenance metadata, legal hold vs retention, and building a regulator-ready export pack.

Operations

Running detection & response for many tenants at once

Per-tenant isolation, consolidated operations, and the guardrails that make multi-tenant SOC work safe.

Get the first posts

We'll email you when we publish. No newsletter spam — just the writing.

Notify me at contact@nirvet.com