Security
Keeping AI infrastructure safe: injection checks, poisoning defences and tenant isolation. 27 articles.
Subscribe with RSSPrompt-injection and jailbreak detection at the cache layer
Attackers disguise injections with odd spacing and character swaps. CGUARD normalizes the disguise first, then scans, so the trick that beats a naive filter doesn't beat this.
More articles
-
The five gates every write passes before it can poison your cache
In any shared cache, one crafted answer could get served to thousands. So every write runs a five-stage gauntlet before it's ever eligible to be reused.
-
Input guardrails (CGUARD): how it works and when to use it
Input guardrails (CGUARD), scans prompts for injection and jailbreaks after normalizing leetspeak, whitespace, and zero-width evasion, model-free and stateless. Here's how Crowkis does it and why it matters for cost and safety.
-
Output guardrails (COUTCHECK): how it works and when to use it
Output guardrails (COUTCHECK), scans responses for PII, toxicity, and JSON validity before they ship, so the model's output is checked at the trust boundary. Here's how Crowkis does it and why it matters for cost and safety.
-
Tenant isolation is a feature you test, not a checkbox you claim
Every multi-tenant product says its tenants are isolated. The ones you can trust are the ones that try to break it on purpose. Here's how we prove no tenant can read another's data.
-
Cache poisoning is the whole problem with semantic caches
Cache poisoning is the whole problem with semantic caches. A practical, Crowkis-grounded take, no hype, just what actually moves cost, latency, and safety.
-
Negative / anti-hallucination cache (CFLAG): how it works and when to use it
Negative / anti-hallucination cache (CFLAG), records known-bad answers so every paraphrase of the question that would reproduce a hallucination is caught. Here's how Crowkis does it and why it matters for cost and safety.
-
PII scrubbing and right-to-erasure (CPII): how it works and when to use it
PII scrubbing and right-to-erasure (CPII), reports what personal data is cached and executes right-to-erasure on request, so compliance is a command. Here's how Crowkis does it and why it matters for cost and safety.
-
Multi-tenant isolation: how it works and when to use it
Multi-tenant isolation, namespaces keys per tenant and tags every entry, so one customer's answer can never be served to another. Here's how Crowkis does it and why it matters for cost and safety.
-
Prompt injection meets your cache: the attack nobody threat-modeled
Injected instructions in one response become served truth for every similar query, unless the cache can smell an answer that doesn't answer.
-
The supply-chain argument, made carefully
After the 2026 gateway compromise, 'how many packages are in your hot path?' became a real procurement question. Our answer is a number: zero.
-
Tenant isolation as physics, not policy
A WHERE clause is a promise; a namespace is a wall. How Crowkis makes cross-tenant leakage structurally impossible rather than procedurally unlikely.
-
PII in a cache: scrub, isolate, erase, prove
Users put personal data in prompts whether you like it or not. The cache's job is a full lifecycle: keep it out of shared entries, find it on demand, erase it provably.
-
Fail closed: why misconfiguring Crowkis locks it instead of opening it
Most self-hosted breaches are defaults, not exploits. Crowkis inverts the failure direction: forget to configure auth and you get a locked deployment, not an open one.
-
The trust ledger: institutional memory for an immune system
Every accept and refuse, per source, append-only. Trust with memory changes attacker economics, and gives auditors the artifact they actually want.
-
Air-gapped by design: AI caching where the internet isn't invited
No phone-home, offline license verification, one binary. The deployment story for networks that treat outbound packets as incidents.
-
Compliance modes: HIPAA, SOC2, GDPR-EU, FedRAMP as configuration
Each regime wants specific retention, audit, and erasure behavior. Enterprise compliance modes preset the whole posture, so the auditor's checklist maps to a flag.
-
Four doors, four locks: the authentication architecture
RESP, gRPC, REST, and the dashboard each get auth that fits their use, constant-time tokens for the data plane, RBAC for the control plane, mandatory locks past loopback.
-
Closed-source as a security posture, argued honestly
'Many eyes' assumes the eyes show up. For your hot path, a signed single binary with zero dependencies is a smaller attack surface than a thousand auditable packages nobody audits.
-
Cache poisoning is the whole problem
Semantic caching has an obvious failure mode nobody likes to talk about: one bad write, served forever to everyone nearby. This is how Crowkis decides what to trust.
-
A practical guide to AI guardrails
A practical guide to AI guardrails. A practical, Crowkis-grounded take, no hype, just what actually moves cost, latency, and safety.
-
How to reduce LLM hallucinations in production
How to reduce LLM hallucinations in production. A practical, Crowkis-grounded take, no hype, just what actually moves cost, latency, and safety.