<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Highflame Blog</title><description>Field notes on agent identity, runtime policy, and securing autonomous AI.</description><link>https://highflame.com/</link><language>en-us</language><atom:link href="https://highflame.com/blog/rss.xml" rel="self" type="application/rss+xml"/><item><title>Three Gateways, One Decision Fabric</title><link>https://highflame.com/blog/three-gateways-one-decision-fabric/</link><guid isPermaLink="true">https://highflame.com/blog/three-gateways-one-decision-fabric/</guid><description>AI security now depends on three control planes: content inspection, tool brokering, and runtime authorization. The problem is not whether your stack has all three. It’s whether they operate as one decision path, sharing identity, detection signals, policy state, and delegation context in real time.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><category>Engineering</category></item><item><title>Highflame + Tailscale Aperture Now Blocks Risky AI Traffic in Real Time</title><link>https://highflame.com/blog/highflame-tailscale-aperture-now-blocks-risky-ai-traffic-in-real-time/</link><guid isPermaLink="true">https://highflame.com/blog/highflame-tailscale-aperture-now-blocks-risky-ai-traffic-in-real-time/</guid><description>Highflame and Tailscale Aperture now enable real-time AI traffic enforcement at the network layer, helping teams detect, govern, and block risky LLM requests before they reach model providers.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>Product</category></item><item><title>Mission Drift: Why AI Agents Fail at Step 100</title><link>https://highflame.com/blog/mission-drift-why-ai-agents-fail-at-step-100/</link><guid isPermaLink="true">https://highflame.com/blog/mission-drift-why-ai-agents-fail-at-step-100/</guid><description>Description: AI agents do not always fail with a crash. They drift. Learn why Step 1 testing and passive observability cannot stop Mission Drift, and how Highflame Compass provides runtime enforcement to keep autonomous agents aligned through Step 100.</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><category>Research</category></item><item><title>The Uniformed Guard Problem: Why AI Agent Sandboxes Need Identity, Not Just Policy</title><link>https://highflame.com/blog/the-uniformed-guard-problem-why-ai-agent-sandboxes-need-identity-not-just-policy/</link><guid isPermaLink="true">https://highflame.com/blog/the-uniformed-guard-problem-why-ai-agent-sandboxes-need-identity-not-just-policy/</guid><description>AI agent sandboxes aren’t enough. Learn why identity, not just policy, is critical to securing autonomous AI systems and preventing misuse.</description><pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate><category>Product</category></item><item><title>Your agent followed every rule. It still broke policy.</title><link>https://highflame.com/blog/your-agent-followed-every-rule-it-still-broke-policy/</link><guid isPermaLink="true">https://highflame.com/blog/your-agent-followed-every-rule-it-still-broke-policy/</guid><description>A new Atlassian paper reveals “policy-invisible violations”, when LLM agents make correct decisions that still break policy. Learn why prompts and DLP fail, and how state-aware enforcement fixes it.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><category>Security</category></item><item><title>When AI Monitors Betray You: The Failure of LLM-as-Judge Architectures</title><link>https://highflame.com/blog/when-ai-monitors-betray-you/</link><guid isPermaLink="true">https://highflame.com/blog/when-ai-monitors-betray-you/</guid><description>A new Berkeley study shows AI models will lie, cheat, and sabotage tasks to protect other models. This breaks LLM-as-judge architectures and exposes a critical flaw in AI safety. Here’s why deterministic guardrails are now essential.</description><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate><category>Research</category></item><item><title>Why Meta’s AI Alignment Director Couldn&apos;t Stop Her Own Agent, and How to Fix It</title><link>https://highflame.com/blog/why-metas-ai-alignment-director-couldnt-stop-her-own-agent--and-how-to-fix-it/</link><guid isPermaLink="true">https://highflame.com/blog/why-metas-ai-alignment-director-couldnt-stop-her-own-agent--and-how-to-fix-it/</guid><description>A technical breakdown of Summer Yue’s 2026 OpenClaw incident. Learn why &quot;in-band&quot; prompt engineering fails and how ZeroID provides out-of-band deterministic control for agents.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate><category>Research</category></item><item><title>Deconstructing “Agents of Chaos”: Failures Behind Autonomous Agent Attacks</title><link>https://highflame.com/blog/deconstructing-agents-of-chaos-authorization-failures-behind-autonomous-agent-attacks/</link><guid isPermaLink="true">https://highflame.com/blog/deconstructing-agents-of-chaos-authorization-failures-behind-autonomous-agent-attacks/</guid><description>Deconstructing “Agents of Chaos” to reveal why AI agent failures stem from missing identity, authorization, and execution control layers.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><category>Security</category></item><item><title>Who Sent You? Solving the Agent Identity Crisis with Highflame ZeroID</title><link>https://highflame.com/blog/who-sent-you-solving-the-agent-identity-crisis/</link><guid isPermaLink="true">https://highflame.com/blog/who-sent-you-solving-the-agent-identity-crisis/</guid><description>Enterprise security teams are blocking AI agents due to identity gaps. Learn how ZeroID provides cryptographic identity, scoped delegation, and instant revocation for autonomous agents.</description><pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate><category>Product</category></item><item><title>Introducing ZeroID: Open Source Identity for Autonomous Agents</title><link>https://highflame.com/blog/introducing-zeroid-open-source-identity-for-autonomous-agents/</link><guid isPermaLink="true">https://highflame.com/blog/introducing-zeroid-open-source-identity-for-autonomous-agents/</guid><description>Introducing ZeroID, an open source identity platform built for autonomous agents. Cryptographically verifiable agent identities, explicit delegation chains, and auditable authorization. Built for the agentic era.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate><category>Product</category></item><item><title>Highflame Partners with Tailscale to Help Secure AI Agents at the Network Layer</title><link>https://highflame.com/blog/highflame-partners-with-tailscale-to-help-secure-ai-agents-at-the-network-layer/</link><guid isPermaLink="true">https://highflame.com/blog/highflame-partners-with-tailscale-to-help-secure-ai-agents-at-the-network-layer/</guid><description>Highflame and Tailscale partner to secure AI agents at the network layer. Monitor and evaluate LLM prompts, tool calls, and responses in real time, without modifying agents.</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate><category>Company</category></item><item><title>The LiteLLM Supply Chain Attack Wasn’t Just a Supply Chain Problem</title><link>https://highflame.com/blog/the-litellm-supply-chain-attack-wasnt-just-a-supply-chain-problem/</link><guid isPermaLink="true">https://highflame.com/blog/the-litellm-supply-chain-attack-wasnt-just-a-supply-chain-problem/</guid><description>The LiteLLM attack exposed a critical gap in AI security. Learn why the focus must shift from data access to controlling agent actions at runtime.</description><pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate><category>Security</category></item><item><title>Traditional Authentication Isn’t Enough for Agent &amp; MCP Security</title><link>https://highflame.com/blog/authentication-isnt-enough/</link><guid isPermaLink="true">https://highflame.com/blog/authentication-isnt-enough/</guid><description>As AI agents gain the ability to call tools through MCP (Model Context Protocol), they move from generating text to executing real actions inside production systems. Most implementations rely on authentication to secure these interactions, assuming that verifying user identity is enough. In practice, authentication only answers who made a request, not whether the request should be allowed. This article explores the security gaps that emerge when AI agents can autonomously choose which tools to execute. We walk through how privilege escalation, cross-tenant data access, and unexpected destructive actions can occur even when requests are properly authenticated. We then outline the additional layers MCP systems need in order to operate safely in production: authorization policies that govern tool execution and inspection mechanisms that analyze the content flowing through MCP requests and responses. For teams building MCP-enabled systems, authentication should be the starting point, not the security model.</description><pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate><category>Product</category></item><item><title>Securely Rolling Out Claude Cowork Across Your Organization</title><link>https://highflame.com/blog/securely-rolling-out-claude-cowork-across-your-organization/</link><guid isPermaLink="true">https://highflame.com/blog/securely-rolling-out-claude-cowork-across-your-organization/</guid><description>Learn how to safely roll out AI tools like Claude Cowork in the enterprise using identity-aware MCP access control to manage permissions across teams and systems.</description><pubDate>Fri, 06 Mar 2026 00:00:00 GMT</pubDate><category>Engineering</category></item><item><title>Securing Intent : The Next Frontier in AI Agent Protection</title><link>https://highflame.com/blog/securing-intent/</link><guid isPermaLink="true">https://highflame.com/blog/securing-intent/</guid><description>As agents gain autonomy and multi-step reasoning becomes the norm, security systems must evolve from snapshot classifiers to trajectory-aware monitors. Because in agent systems, risk isn’t a single moment. It’s a direction. And direction can only be detected if your security layer remembers where you’ve been.</description><pubDate>Tue, 24 Feb 2026 00:00:00 GMT</pubDate><category>Research</category></item><item><title>Unified Control Plane for Enterprise Code Agent Security</title><link>https://highflame.com/blog/unified-control-plane-for-enterprise-code-agent-security/</link><guid isPermaLink="true">https://highflame.com/blog/unified-control-plane-for-enterprise-code-agent-security/</guid><description>Unified threat detection, exfiltration prevention, safe MCP usage and global policy enforcement for Claude Code, Cursor, and all your enterprise code agents.</description><pubDate>Mon, 26 Jan 2026 00:00:00 GMT</pubDate><category>Engineering</category></item><item><title>Agent Context Graphs and Safe Autonomy</title><link>https://highflame.com/blog/agent-context-graphs-semantic-intelligence-safe-autonomy/</link><guid isPermaLink="true">https://highflame.com/blog/agent-context-graphs-semantic-intelligence-safe-autonomy/</guid><description>Why logs fail for agentic AI and how context graphs and semantic intelligence create a system of record for governing autonomous systems.</description><pubDate>Mon, 19 Jan 2026 00:00:00 GMT</pubDate><category>Research</category></item><item><title>Palisade is now available on Github Marketplace</title><link>https://highflame.com/blog/palisade-is-now-available-on-github-marketplace/</link><guid isPermaLink="true">https://highflame.com/blog/palisade-is-now-available-on-github-marketplace/</guid><description>Palisade is now available on Github Marketplace</description><pubDate>Mon, 12 Jan 2026 00:00:00 GMT</pubDate><category>Company</category></item><item><title>DeepContext: Defending Against Multi-Turn LLM Attacks with Context-Aware Guardrails</title><link>https://highflame.com/blog/deepcontext-defending-against-multi-turn-llm-attacks-with-context-aware-guardrails/</link><guid isPermaLink="true">https://highflame.com/blog/deepcontext-defending-against-multi-turn-llm-attacks-with-context-aware-guardrails/</guid><description>LLM attacks evolve across turns. Learn why memory, semantic intelligence, and continuous defenses are essential for safe AI systems.</description><pubDate>Tue, 06 Jan 2026 00:00:00 GMT</pubDate><category>Company</category></item><item><title>Launching Palisade: Zero-Trust Security for the AI Model Supply Chain</title><link>https://highflame.com/blog/launching-palisade-zero-trust-security-for-the-ai-model-supply-chain/</link><guid isPermaLink="true">https://highflame.com/blog/launching-palisade-zero-trust-security-for-the-ai-model-supply-chain/</guid><description>The AI ecosystem has a security blind spot.</description><pubDate>Thu, 18 Dec 2025 00:00:00 GMT</pubDate><category>Company</category></item><item><title>How We Built Highflame RedTeam: An Agent-Powered AI Red Teaming System</title><link>https://highflame.com/blog/how-we-built-highflame-redteam-an-agent-powered-ai-red-teaming-system/</link><guid isPermaLink="true">https://highflame.com/blog/how-we-built-highflame-redteam-an-agent-powered-ai-red-teaming-system/</guid><description>Our security platform, Highflame Red, uses a team of specialized AI agents to automatically discover vulnerabilities in LLM applications. Taking this system from a concept to a production-ready platform taught us critical lessons about system architecture, dynamic attack generation, and automated evaluation.</description><pubDate>Fri, 03 Oct 2025 00:00:00 GMT</pubDate><category>Security</category></item><item><title>Introducing Overwatch: Code Agent Security</title><link>https://highflame.com/blog/code-agent-security-at-the-developers-fingertips/</link><guid isPermaLink="true">https://highflame.com/blog/code-agent-security-at-the-developers-fingertips/</guid><description>Protect your development environment with Overwatch, a lightweight IDE plugin that monitors local MCP servers, blocks unauthorized connections, and prevents malicious code injections. Secure your code agents effortlessly while keeping your workflow fast and uninterrupted.</description><pubDate>Wed, 24 Sep 2025 00:00:00 GMT</pubDate><category>Company</category></item><item><title>When Agents Chain Tools, The Risk Multiplies</title><link>https://highflame.com/blog/when-agents-chain-tools-the-risk-multiplies/</link><guid isPermaLink="true">https://highflame.com/blog/when-agents-chain-tools-the-risk-multiplies/</guid><description>AI agents can unintentionally chain tools and expose sensitive data. Learn how to prevent privilege escalation, enforce policies, and scale AI securely.</description><pubDate>Tue, 16 Sep 2025 00:00:00 GMT</pubDate><category>Engineering</category></item><item><title>Announcing the Ramparts MCP Toolkit on Docker Hub</title><link>https://highflame.com/blog/announcing-the-ramparts-mcp-toolkit-on-docker-hub/</link><guid isPermaLink="true">https://highflame.com/blog/announcing-the-ramparts-mcp-toolkit-on-docker-hub/</guid><description>Get an MCP security scan in under two minutes. Ramparts makes setup as simple as a Docker pull.</description><pubDate>Wed, 10 Sep 2025 00:00:00 GMT</pubDate><category>Company</category></item><item><title>Why Enterprise AI Agent Security Can’t Rely on Platform Providers Alone</title><link>https://highflame.com/blog/why-enterprise-ai-agent-security-cant-rely-on-platform-providers-alone/</link><guid isPermaLink="true">https://highflame.com/blog/why-enterprise-ai-agent-security-cant-rely-on-platform-providers-alone/</guid><description>73% of enterprises face AI security incidents. Platform-native tools miss runtime threats and compliance. Learn why specialized AI agent security is essential.</description><pubDate>Wed, 03 Sep 2025 00:00:00 GMT</pubDate><category>Research</category></item><item><title>Highflame joins Coalition for Secure AI</title><link>https://highflame.com/blog/highglame-joins-the-coalition-for-secure-ai/</link><guid isPermaLink="true">https://highflame.com/blog/highglame-joins-the-coalition-for-secure-ai/</guid><description>Highflame is proud to partner with the Coalition for Secure AI (CoSAI), working alongside industry leaders to advance open standards, strengthen AI supply chain security, and support responsible enterprise adoption.</description><pubDate>Thu, 28 Aug 2025 00:00:00 GMT</pubDate><category>Company</category></item><item><title>Securing the Bridge: Where AI meets Enterprise Data</title><link>https://highflame.com/blog/securing-the-bridge-where-ai-meets-enterprise-data/</link><guid isPermaLink="true">https://highflame.com/blog/securing-the-bridge-where-ai-meets-enterprise-data/</guid><description>Secure AI with MCP security: mitigate risks like prompt injection, tool poisoning, and excessive permissions across enterprise data and AI workflows</description><pubDate>Tue, 26 Aug 2025 00:00:00 GMT</pubDate><category>Engineering</category></item><item><title>Why GPT-5’s Capabilities Are a Double-Edged Sword for Enterprise Security</title><link>https://highflame.com/blog/why-gpt-5s-capabilities-are-a-double-edged-sword-for-enterprise-security/</link><guid isPermaLink="true">https://highflame.com/blog/why-gpt-5s-capabilities-are-a-double-edged-sword-for-enterprise-security/</guid><description>With GPT-5, enterprises gain new automation and reasoning potential, but attackers move just as fast. See how Highflame secures agents and MCP-connected tools</description><pubDate>Thu, 21 Aug 2025 00:00:00 GMT</pubDate><category>Research</category></item><item><title>5 Blackhat 2025 Takeaways on AI &amp; Automation Security</title><link>https://highflame.com/blog/5-blackhat-2025-takeaways-on-ai-automation-security/</link><guid isPermaLink="true">https://highflame.com/blog/5-blackhat-2025-takeaways-on-ai-automation-security/</guid><description>Secure AI models, agents, and pipelines with governance, identity-aware access, runtime protections, AI-vs-AI detection + model hardening, and human-in-the-loop controls.</description><pubDate>Fri, 15 Aug 2025 00:00:00 GMT</pubDate><category>Research</category></item><item><title>Announcing Ramparts: Securing MCP usage</title><link>https://highflame.com/blog/ramparts-mcp-scan/</link><guid isPermaLink="true">https://highflame.com/blog/ramparts-mcp-scan/</guid><description>Ramparts is a high-performance Rust MCP scanner that uncovers security vulnerabilities in Model Context Protocol servers. Lightweight, safe, and CI-ready.</description><pubDate>Tue, 22 Jul 2025 00:00:00 GMT</pubDate><category>Company</category></item><item><title>Why traditional DLP hurts LLM accuracy?</title><link>https://highflame.com/blog/why-traditional-dlp-hurts-llm-accuracy/</link><guid isPermaLink="true">https://highflame.com/blog/why-traditional-dlp-hurts-llm-accuracy/</guid><description>Traditional data loss prevention (DLP) tools distort LLM prompts and outputs, degrading accuracy and trust. These disruptions lead to unreliable responses, broken user experiences, and slower enterprise AI adoption. Discover why modern LLM security offers a better path forward.</description><pubDate>Thu, 10 Jul 2025 00:00:00 GMT</pubDate><category>Company</category></item><item><title>Javelin Guard: Next-Generation Security Models</title><link>https://highflame.com/blog/next-gen-security-models/</link><guid isPermaLink="true">https://highflame.com/blog/next-gen-security-models/</guid><description>Static rules and blacklists weren’t built for the complexity of modern LLM interactions. Discover a new approach: next-gen security models that evaluate intent, adapt in real time, and align with how enterprise teams actually use generative AI.</description><pubDate>Fri, 30 May 2025 00:00:00 GMT</pubDate><category>Company</category></item><item><title>​AI Agent Authentication Security: Prevent Spoofing, Prompt Injection, and Abuse</title><link>https://highflame.com/blog/ai-agent-authentication-security/</link><guid isPermaLink="true">https://highflame.com/blog/ai-agent-authentication-security/</guid><description>Protect enterprise AI workflows from agent impersonation, unauthorized access, and data exposure. Explore security-first practices for LLM agent authentication and control.</description><pubDate>Tue, 13 May 2025 00:00:00 GMT</pubDate><category>Product</category></item><item><title>Top 5 Takeaways for CISOs from RSAC 2025:</title><link>https://highflame.com/blog/top-5-takeaways-for-cisos-from-rsac-2025-66as2/</link><guid isPermaLink="true">https://highflame.com/blog/top-5-takeaways-for-cisos-from-rsac-2025-66as2/</guid><description>From RSAC 2025: AI security demands a full-lifecycle strategy, identity is now the new perimeter, and open-source collaboration is reshaping threat defense. Explore five key insights every CISO needs to navigate the evolving landscape of enterprise and AI security.</description><pubDate>Tue, 13 May 2025 00:00:00 GMT</pubDate><category>Research</category></item><item><title>Enterprise Strategies for MCP Integration</title><link>https://highflame.com/blog/securing-the-model-context-protocol/</link><guid isPermaLink="true">https://highflame.com/blog/securing-the-model-context-protocol/</guid><description>Model Context Protocol (MCP) integrations unlock flexible AI agents, but also introduce new security challenges. Explore how to protect MCP workflows with strong authentication, tool permissions, input/output controls, real-time monitoring, and auditability.</description><pubDate>Wed, 16 Apr 2025 00:00:00 GMT</pubDate><category>Company</category></item><item><title>Highflame achieves SOC2 compliance</title><link>https://highflame.com/blog/highflame-achieves-soc2-compliance/</link><guid isPermaLink="true">https://highflame.com/blog/highflame-achieves-soc2-compliance/</guid><description>Highflame is the end-to-end real-time AI platform for enterprises building and adopting AI products</description><pubDate>Sat, 12 Apr 2025 00:00:00 GMT</pubDate><category>Company</category></item><item><title>AI Runtime Security: How to Protect Your GenAI Stack from Real-World Threats</title><link>https://highflame.com/blog/ai-runtime-security-how-to-protect-your-genai-stack-from-real-world-threats/</link><guid isPermaLink="true">https://highflame.com/blog/ai-runtime-security-how-to-protect-your-genai-stack-from-real-world-threats/</guid><description>Enforce real-time guardrails, monitor AI behavior, and ensure secure, compliant AI performance in production.</description><pubDate>Wed, 02 Apr 2025 00:00:00 GMT</pubDate><category>Company</category></item><item><title>Secure your AI Embeddings with Homomorphic Encryption</title><link>https://highflame.com/blog/secure-your-ai-embeddings-with-homomorphic-encryption/</link><guid isPermaLink="true">https://highflame.com/blog/secure-your-ai-embeddings-with-homomorphic-encryption/</guid><description>Protect sensitive enterprise data in LLM applications with homomorphic encryption for embeddings. Highflame enables private similarity search and inference without exposing raw vectors, supporting compliance, zero-trust architecture, and full auditability across your AI pipelines.</description><pubDate>Fri, 08 Nov 2024 00:00:00 GMT</pubDate><category>Company</category></item></channel></rss>