We built software supply chain security around one idea: know your dependencies, track every version, trace every change. An SBOM tells you exactly what's in your code. Now ask what tells you what's in your agent's model — which checkpoint answered, what data trained it, what
We lead in security of Cloud, AI and Zero Trust. Follow our research, education, certification and events.
- Most companies treat AI security as a checkbox for after launch — ship the agent, then bolt on guardrails once someone in legal asks a hard question. By then it's already touched every system you didn't mean to expose it to. TAISE is for teams who'd rather design that control in
- Ask around your org: who owns the security of your AI agents once they start acting on their own? AppSec says it's a model problem. The AI team says it's a security problem. Cloud security says it's not in their remit. Meanwhile the agent has API access and nobody's name is on
- Three separate agent platforms — AWS Bedrock AgentCore, Google's Agent Development Kit, Vercel AI SDK — just got flagged for the same structural flaw, dubbed CoreBreak: attackers can trigger tool execution by forging tool-call blocks that skip the model turn entirely. No prompt
- CISO Daily Briefing: Patch TeamCity now — CVE-2026-63077 (CVSS 9.8), added to CISA's KEV, Aug 8 deadline, build-server creds at risk. CoreBreak flaws in AWS Bedrock, Google ADK, Vercel's AI SDK trigger tool calls with zero model turn, bypassing filters; all three patched.

