[{"data":1,"prerenderedAt":1798},["ShallowReactive",2],{"{\"cv\":1786654911610,\"version\":\"published\"}widgets\u002Fnavigation-bar":3,"{\"cv\":1786654911610,\"resolve_relations\":[\"ResourceFeatureCard.resource\"],\"version\":\"published\"}case-studies\u002Fsecuring-the-ai-development-lifecycle":66},{"data":4,"headers":45},{"story":5,"cv":42,"rels":43,"links":44},{"name":6,"created_at":7,"published_at":8,"updated_at":9,"id":10,"uuid":11,"content":12,"slug":32,"full_slug":33,"sort_by_date":22,"position":34,"tag_list":35,"is_startpage":15,"parent_id":36,"meta_data":22,"group_id":37,"first_published_at":38,"release_id":22,"lang":39,"path":40,"alternates":41,"default_full_slug":22,"translated_slugs":22},"Navigation Bar","2026-08-05T05:55:49.585Z","2026-08-07T15:41:09.255Z","2026-08-07T15:41:09.269Z",205700094329908,"be34732b-2155-45e7-8ee2-86e1157a8cb4",{"_uid":13,"component":14,"showMarketingBanner":15,"marketingBannerContent":16},"e7a8d72d-8af8-452e-87b2-de4098162fb9","NavigationBar",false,{"type":17,"content":18},"doc",[19],{"type":20,"attrs":21,"content":23},"paragraph",{"textAlign":22},null,[24],{"text":25,"type":26,"marks":27},"See us at Black Hat booth #7505","text",[28],{"type":29,"attrs":30},"textStyle",{"color":31},"#000000","navigation-bar","widgets\u002Fnavigation-bar",0,[],205696803161001,"e116d2fb-7cac-4697-9dcb-91d9283aecc3","2026-08-05T06:19:33.200Z","default","\u002F",[],1786654679,[],[],{"cache-control":46,"connection":47,"content-length":48,"content-type":49,"date":50,"etag":51,"referrer-policy":52,"sb-be-version":53,"server":54,"vary":55,"via":56,"x-amz-cf-id":57,"x-amz-cf-pop":58,"x-cache":59,"x-content-type-options":60,"x-frame-options":61,"x-permitted-cross-domain-policies":62,"x-request-id":63,"x-runtime":64,"x-xss-protection":65},"max-age=0, public, s-maxage=604800, stale-if-error=3600","keep-alive","986","application\u002Fjson; charset=utf-8","Thu, 13 Aug 2026 21:02:21 GMT","W\u002F\"6f15609f6622677bb823fe979b6299c5\"","strict-origin-when-cross-origin","5.941.0","nginx\u002F1.29.1","Origin","1.1 2733aa94cc15bc99c6328b4e904aa4cc.cloudfront.net (CloudFront)","n3yA5k1sGF1b7Wr4qAuOwjOT7xwFK56yclKVoylLbtI4evqsUGDoWQ==","CMH68-P7","Miss from cloudfront","nosniff","SAMEORIGIN","none","78257a34-20b2-4891-976d-ffb29348dd32","0.023761","0",{"data":67,"headers":1788},{"story":68,"cv":42,"rels":1169,"links":1787},{"name":69,"created_at":70,"published_at":71,"updated_at":72,"id":73,"uuid":74,"content":75,"slug":1163,"full_slug":1164,"sort_by_date":22,"position":1165,"tag_list":1166,"is_startpage":15,"parent_id":1147,"meta_data":22,"group_id":1167,"first_published_at":71,"release_id":22,"lang":39,"path":22,"alternates":1168,"default_full_slug":22,"translated_slugs":22},"Securing the AI Development Lifecycle","2026-08-13T19:22:11.586Z","2026-08-13T20:13:14.083Z","2026-08-13T20:13:14.101Z",208729422203394,"162e90db-785b-438f-8c3e-989f3a916678",{"Tags":76,"_uid":77,"title":69,"content":78,"component":518,"seoOgImage":519,"previewImage":526,"previewTitle":528,"relatedContent":529,"seoDescription":1150,"previewDescription":1151,"shortOutcomeDescription":1152},"SOC, MSSP, incident response, MTTC, vulnerability management, NIST RMF","e0f10234-7a3c-4061-838a-bac232c782ad",{"type":17,"attrs":79,"content":80},{"backgroundColor":22},[81,93,101,121,129,140,148,168,186,204,222,240,258,267,275,283,301,319,336,354,363,371,380,388,396,404,413,421,429,437,445,453,461,470,478,486,494,502,510],{"type":82,"attrs":83,"content":85},"heading",{"level":84,"textAlign":22},2,[86],{"text":87,"type":26,"marks":88},"AI pipelines aggregating patient genomic data and electronic consent records represent exactly the kind of high-value, under-secured infrastructure that sophisticated attackers actively target.",[89,91],{"type":29,"attrs":90},{"color":31},{"type":92},"bold",{"type":20,"attrs":94,"content":95},{"textAlign":22},[96],{"text":97,"type":26,"marks":98},"ConsentVault deploys AI tools to manage structured clinical data, genomic ingestion pipelines, and patient eConsent workflows across research and community oncology settings. When the organization evaluated how to protect this infrastructure, the answer was not a better detection tool. It was a different architecture entirely.",[99],{"type":29,"attrs":100},{"color":31},{"type":20,"attrs":102,"content":103},{"textAlign":22},[104,109,116],{"text":105,"type":26,"marks":106},"In clinical AI environments, detecting a breach of non-anonymous biological data or a corrupted consent record after the fact is a failure. Patient genomic information cannot be rotated like a compromised password or reissued like a stolen credential. A consent record that an adversary has accessed or altered cannot be un-accessed. The standard reactive posture of ",[107],{"type":29,"attrs":108},{"color":31},{"text":110,"type":26,"marks":111},"detect, alert, respond",[112,114],{"type":29,"attrs":113},{"color":31},{"type":115},"italic",{"text":117,"type":26,"marks":118}," has no meaningful remediation step when the data involved is both irreplaceable and legally binding.",[119],{"type":29,"attrs":120},{"color":31},{"type":20,"attrs":122,"content":123},{"textAlign":22},[124],{"text":125,"type":26,"marks":126},"Xiid's Terniion platform gave ConsentVault a fundamentally different foundation: not a detection layer, but a deterministic security architecture that removes infrastructure from the attack surface before exposure is possible, eliminates credentials from the wire, and enforces process-level isolation across every data flow without degrading the throughput that AI training workloads require.",[127],{"type":29,"attrs":128},{"color":31},{"type":82,"attrs":130,"content":132},{"level":131,"textAlign":22},3,[133],{"text":134,"type":26,"marks":135},"Industry Challenge: The Unique Threat Model of Clinical AI",[136,139],{"type":29,"attrs":137},{"color":138},"#F68D2E",{"type":92},{"type":20,"attrs":141,"content":142},{"textAlign":22},[143],{"text":144,"type":26,"marks":145},"Across oncology research, community clinical practice, and pharmaceutical-sponsored trial operations, AI-enabled healthcare organizations face a threat model that is structurally different from general enterprise security:",[146],{"type":29,"attrs":147},{"color":31},{"type":149,"content":150},"bullet_list",[151],{"type":152,"content":153},"list_item",[154],{"type":20,"attrs":155,"content":156},{"textAlign":22},[157,163],{"text":158,"type":26,"marks":159},"Healthcare is the most targeted sector.",[160,162],{"type":29,"attrs":161},{"color":31},{"type":92},{"text":164,"type":26,"marks":165}," The industry reported more cyberthreats in 2024 than any other sector. Attackers prioritize healthcare because the combination of sensitive data, compliance pressure, and operational urgency creates both high-value targets and favorable conditions for coercion.",[166],{"type":29,"attrs":167},{"color":31},{"type":149,"content":169},[170],{"type":152,"content":171},[172],{"type":20,"attrs":173,"content":174},{"textAlign":22},[175,181],{"text":176,"type":26,"marks":177},"Genomic data cannot be remediated after compromise.",[178,180],{"type":29,"attrs":179},{"color":31},{"type":92},{"text":182,"type":26,"marks":183}," Unlike passwords, tokens, or even financial records, patient genomic information is permanent and uniquely identifying. A single exfiltration event creates a permanent exposure. There is no credential rotation that addresses it.",[184],{"type":29,"attrs":185},{"color":31},{"type":149,"content":187},[188],{"type":152,"content":189},[190],{"type":20,"attrs":191,"content":192},{"textAlign":22},[193,199],{"text":194,"type":26,"marks":195},"AI ingestion pipelines are under-secured by design.",[196,198],{"type":29,"attrs":197},{"color":31},{"type":92},{"text":200,"type":26,"marks":201}," The same connectivity that makes AI systems powerful—continuous data ingestion from distributed sources, access to data lakes and document stores, integration with external clinical systems—creates attack surface that conventional perimeter tools were not built to address. Pipelines that ingest data at AI scale cannot be protected by approaches that require interrupting the data flow.",[202],{"type":29,"attrs":203},{"color":31},{"type":149,"content":205},[206],{"type":152,"content":207},[208],{"type":20,"attrs":209,"content":210},{"textAlign":22},[211,217],{"text":212,"type":26,"marks":213},"Model poisoning is a clinical safety risk.",[214,216],{"type":29,"attrs":215},{"color":31},{"type":92},{"text":218,"type":26,"marks":219}," In clinical AI systems, data manipulation is both a security incident and a patient safety event. An adversary who can alter the data feeding a diagnostic or treatment AI doesn't just steal information. They corrupt the decisions that follow from it.",[220],{"type":29,"attrs":221},{"color":31},{"type":149,"content":223},[224],{"type":152,"content":225},[226],{"type":20,"attrs":227,"content":228},{"textAlign":22},[229,235],{"text":230,"type":26,"marks":231},"Compliance is non-negotiable, but it doesn't equal security.",[232,234],{"type":29,"attrs":233},{"color":31},{"type":92},{"text":236,"type":26,"marks":237}," HIPAA and EU GDPR establish minimum standards for data handling. They do not require and cannot substitute for an architecture that prevents unauthorized access from occurring in the first place. Attestation of compliance after a breach does not undo the breach.",[238],{"type":29,"attrs":239},{"color":31},{"type":149,"content":241},[242],{"type":152,"content":243},[244],{"type":20,"attrs":245,"content":246},{"textAlign":22},[247,253],{"text":248,"type":26,"marks":249},"eConsent records carry legal weight that detection cannot protect.",[250,252],{"type":29,"attrs":251},{"color":31},{"type":92},{"text":254,"type":26,"marks":255}," A consent record that has been accessed or altered by an unauthorized party creates liability that survives any subsequent remediation effort. The integrity of the consent process must be guaranteed before exposure occurs, not investigated after.",[256],{"type":29,"attrs":257},{"color":31},{"type":82,"attrs":259,"content":260},{"level":131,"textAlign":22},[261],{"text":262,"type":26,"marks":263},"In Practice: A Government-Focused Managed Services Provider",[264,266],{"type":29,"attrs":265},{"color":138},{"type":92},{"type":20,"attrs":268,"content":269},{"textAlign":22},[270],{"text":271,"type":26,"marks":272},"ConsentVault's platform serves oncology and clinical practices that need to capture, track, and operationalize patient consent for the ethical use of PHI and diagnostic data across treatment, research, and AI-powered analytics. The organization operates at the intersection of several distinct high-sensitivity data types: structured clinical records, patient genomic information, and legally binding eConsent documentation all flowing through AI pipelines that must remain operational without interruption.",[273],{"type":29,"attrs":274},{"color":31},{"type":20,"attrs":276,"content":277},{"textAlign":22},[278],{"text":279,"type":26,"marks":280},"When ConsentVault evaluated its security posture, the threat model it confronted was specific. Terniion does not add another detection layer to address it. It removes the attack surface that detection depends on finding.",[281],{"type":29,"attrs":282},{"color":31},{"type":149,"content":284},[285],{"type":152,"content":286},[287],{"type":20,"attrs":288,"content":289},{"textAlign":22},[290,296],{"text":291,"type":26,"marks":292},"Threat 1: Exfiltration from AI ingestion pipelines.",[293,295],{"type":29,"attrs":294},{"color":31},{"type":92},{"text":297,"type":26,"marks":298}," Genomic data ingested for AI training workloads passes through pipelines that must handle high throughput. Approaches that interrupt data flow to inspect it create operational constraints that are incompatible with AI training at scale.",[299],{"type":29,"attrs":300},{"color":31},{"type":149,"content":302},[303],{"type":152,"content":304},[305],{"type":20,"attrs":306,"content":307},{"textAlign":22},[308,314],{"text":309,"type":26,"marks":310},"Threat 2: Data manipulation and model poisoning.",[311,313],{"type":29,"attrs":312},{"color":31},{"type":92},{"text":315,"type":26,"marks":316}," An adversary with access to a clinical AI training pipeline doesn't need to exfiltrate data to cause harm. They can alter data in place corrupts the downstream model and every decision it produces. ConsentVault ingests third-party data it does not control, which means a compromised upstream source is a realistic attack vector, not a theoretical one.",[317],{"type":29,"attrs":318},{"color":31},{"type":149,"content":320},[321],{"type":152,"content":322},[323],{"type":20,"attrs":324,"content":325},{"textAlign":22},[326,332],{"text":327,"type":26,"marks":328},"Threat 3: eConsent record integrity.",[329,331],{"type":29,"attrs":330},{"color":31},{"type":92},{"text":254,"type":26,"marks":333},[334],{"type":29,"attrs":335},{"color":31},{"type":149,"content":337},[338],{"type":152,"content":339},[340],{"type":20,"attrs":341,"content":342},{"textAlign":22},[343,349],{"text":344,"type":26,"marks":345},"Threat 4: Inference endpoint exposure.",[346,348],{"type":29,"attrs":347},{"color":31},{"type":92},{"text":350,"type":26,"marks":351}," Deployed AI inference endpoints are a distinct and often overlooked attack surface. Unlike training pipelines, inference endpoints must respond to queries in real time which traditionally means they must be reachable. In clinical settings, an exposed inference endpoint is both a data exfiltration vector and a target for adversarial inputs designed to manipulate model outputs.",[352],{"type":29,"attrs":353},{"color":31},{"type":82,"attrs":355,"content":356},{"level":131,"textAlign":22},[357],{"text":358,"type":26,"marks":359},"The Xiid Solution: Eliminate Exposure Before It Becomes a Breach ",[360,362],{"type":29,"attrs":361},{"color":138},{"type":92},{"type":20,"attrs":364,"content":365},{"textAlign":22},[366],{"text":367,"type":26,"marks":368},"Terniion addresses all four through two architectural capabilities.",[369],{"type":29,"attrs":370},{"color":31},{"type":20,"attrs":372,"content":373},{"textAlign":22},[374],{"text":375,"type":26,"marks":376},"1. Make Network and AI Infrastructure Non-Addressable",[377,379],{"type":29,"attrs":378},{"color":31},{"type":92},{"type":20,"attrs":381,"content":382},{"textAlign":22},[383],{"text":384,"type":26,"marks":385},"The most direct way to prevent a breach of AI data infrastructure is to make that infrastructure unreachable to attackers in the first place. Terniion keeps ConsentVault's AI data ingestion pipelines, data lakes, inference endpoints, and document stores completely non-addressable from the internet.",[386],{"type":29,"attrs":387},{"color":31},{"type":20,"attrs":389,"content":390},{"textAlign":22},[391],{"text":392,"type":26,"marks":393},"There are no open inbound ports. There are no exposed services for attackers to find, scan, or probe. The infrastructure is not hidden by a firewall or obscured by a VPN. It is architecturally absent from the attack surface. If an attacker cannot reach a system, they cannot exfiltrate data from it, manipulate its inputs, or poison the models it trains. This applies equally to inference endpoints: they remain fully accessible to authorized processes while remaining invisible to everything else, which resolves the availability-versus-security tradeoff that makes inference endpoints a persistent risk in clinical AI deployments.",[394],{"type":29,"attrs":395},{"color":31},{"type":20,"attrs":397,"content":398},{"textAlign":22},[399],{"text":400,"type":26,"marks":401},"For pharmaceutical sponsors, community oncology practices, and payers evaluating ConsentVault for real-world evidence generation and clinical trial operations, this is the security posture they require: not a promise that breaches will be detected quickly, but a guarantee that the infrastructure cannot be reached.",[402],{"type":29,"attrs":403},{"color":31},{"type":20,"attrs":405,"content":406},{"textAlign":22},[407],{"text":408,"type":26,"marks":409},"2. Enforce Authorized-Only Data Flow",[410,412],{"type":29,"attrs":411},{"color":31},{"type":92},{"type":20,"attrs":414,"content":415},{"textAlign":22},[416],{"text":417,"type":26,"marks":418},"Even inside a secured perimeter, lateral movement remains a persistent risk. An adversary who compromises one system can traverse shared network layers to reach others. In clinical AI environments, where data flows connect consent management, genomic ingestion, training pipelines, and inference endpoints, the potential blast radius of a single compromise is significant.",[419],{"type":29,"attrs":420},{"color":31},{"type":20,"attrs":422,"content":423},{"textAlign":22},[424],{"text":425,"type":26,"marks":426},"Terniion enforces process-to-process isolation structurally. Every data flow operates through its own dedicated, outbound-only, triple-encrypted connection. There is no shared network layer. Lateral movement between processes or environments is architecturally impossible. It’s not restricted by policy but eliminated by design.",[427],{"type":29,"attrs":428},{"color":31},{"type":20,"attrs":430,"content":431},{"textAlign":22},[432],{"text":433,"type":26,"marks":434},"Specifically, if any source of ingested data is compromised by malware or full remote compromise, the data lake is still protected from data poisoning. For ConsentVault's use case, they are ingesting third-party data that they do not control. Terniion provides the necessary layer of security within their partners' environment to ensure the continued integrity of their data pipeline.",[435],{"type":29,"attrs":436},{"color":31},{"type":20,"attrs":438,"content":439},{"textAlign":22},[440],{"text":441,"type":26,"marks":442},"Patient data and AI workloads move only through these isolated tunnels. Clinicians and patients experience no change in how they use the system. The security boundary is invisible to the workflow and absolute to an adversary.",[443],{"type":29,"attrs":444},{"color":31},{"type":20,"attrs":446,"content":447},{"textAlign":22},[448],{"text":449,"type":26,"marks":450},"The result is a security architecture that Patricia Goede, ConsentVault's chief data strategy officer, describes in direct terms: \"Terniion gives us the confidence to let our AI do the hard work on highly sensitive clinical, diagnostic, and treatment data without ever compromising patient privacy or intellectual property security. By wrapping the entire ConsentVault platform in Xiid's encrypted SealedTunnel technology, our inference endpoints, training pipelines, and data repositories are fully isolated from the public internet, which is precisely the security posture pharmaceutical sponsors, community oncology practices, and payers expect when entrusting us with real-world evidence generation and clinical trial operations.\"",[451],{"type":29,"attrs":452},{"color":31},{"type":20,"attrs":454,"content":455},{"textAlign":22},[456],{"text":457,"type":26,"marks":458},"Under active HIPAA and EU GDPR compliance obligations, ConsentVault operates with the confidence that its security posture is architectural, not policy-dependent. Compliance attestation documents what controls are in place. Terniion ensures those controls cannot be bypassed.",[459],{"type":29,"attrs":460},{"color":31},{"type":82,"attrs":462,"content":463},{"level":131,"textAlign":22},[464],{"text":465,"type":26,"marks":466},"Proven Reliability",[467,469],{"type":29,"attrs":468},{"color":138},{"type":92},{"type":20,"attrs":471,"content":472},{"textAlign":22},[473],{"text":474,"type":26,"marks":475},"Terniion carries an unconditional Authority to Operate from the U.S. Department of Defense. This designation has not been awarded to any other cybersecurity vendor. The U.S. Air Force Research Laboratory conducted independent penetration testing in 2024 and declared the infrastructure effectively unreachable to standard attack methodologies.",[476],{"type":29,"attrs":477},{"color":31},{"type":20,"attrs":479,"content":480},{"textAlign":22},[481],{"text":482,"type":26,"marks":483},"Terniion is currently protecting workloads for the Defense Health Agency, CI\u002FCD pipelines for defense contractors, and sensitive data flows across federal agencies, as well as enterprise AI tools and EV charging infrastructure. The platform scales from single endpoints to enterprise environments with tens of thousands of managed assets, with SealedTunnels deployable in under 90 seconds and manageable from a single control plane.",[484],{"type":29,"attrs":485},{"color":31},{"type":82,"attrs":487,"content":488},{"level":131,"textAlign":22},[489],{"text":490,"type":26,"marks":491},"Conclusion",[492],{"type":29,"attrs":493},{"color":138},{"type":20,"attrs":495,"content":496},{"textAlign":22},[497],{"text":498,"type":26,"marks":499},"Clinical AI operates on data that cannot be remediated after compromise. The organizations that recognize this and build their security architecture around preventing exposure rather than detecting it are the ones that can credibly make the promises their clients, partners, and regulators require.",[500],{"type":29,"attrs":501},{"color":31},{"type":20,"attrs":503,"content":504},{"textAlign":22},[505],{"text":506,"type":26,"marks":507},"ConsentVault chose Terniion because the alternative of a detection-dependent posture was structurally incompatible with the threat model it faced. Genomic data doesn't have a recovery path. Consent records carry legal liability that survives any incident response. And the AI pipelines aggregating both were exactly the kind of infrastructure that sophisticated adversaries target.",[508],{"type":29,"attrs":509},{"color":31},{"type":20,"attrs":511,"content":512},{"textAlign":22},[513],{"text":514,"type":26,"marks":515},"Terniion removes that infrastructure from the attack surface entirely. It enforces process-level isolation that makes lateral movement architecturally impossible. And it does all of this without changing how clinicians, researchers, or patients interact with the platform.",[516],{"type":29,"attrs":517},{"color":31},"CaseStudy",{"id":520,"alt":521,"name":521,"focus":521,"title":521,"source":521,"filename":522,"copyright":521,"fieldtype":523,"meta_data":524,"is_external_url":15},208740979252116,"","https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F6144x3456\u002Feba44ae235\u002Fresearcher-looking-monitor-analysing-brain-scan-while-coworker-discussing-with-patient-background-about-side-effects-mind-functions-nervous-system-tomography-scan-working-laboratory.jpg","asset",{"size":525},"6144x3456",{"id":520,"alt":521,"name":521,"focus":521,"title":521,"source":521,"filename":522,"copyright":521,"fieldtype":523,"meta_data":527,"is_external_url":15},{"size":525},"From Ingestion to Inference: A Case for Preventive Security Across the AI Lifecycle | Xiid",[530],{"_uid":531,"variant":532,"resource":533,"component":1129,"background":1130},"6b0de268-b527-4dee-848b-fd745e9d5380","oneThirdLeftPhoto",[534],{"name":535,"created_at":536,"published_at":537,"updated_at":538,"id":539,"uuid":540,"content":541,"slug":1143,"full_slug":1144,"sort_by_date":22,"position":1145,"tag_list":1146,"is_startpage":15,"parent_id":1147,"meta_data":22,"group_id":1148,"first_published_at":537,"release_id":22,"lang":39,"path":22,"alternates":1149,"default_full_slug":22,"translated_slugs":22,"_stopResolving":1128},"Securing dynamic containerized environments","2026-07-23T17:17:13.586Z","2026-07-24T16:06:17.174Z","2026-07-24T16:06:17.192Z",201266927995590,"fb3400f1-470d-4f55-9092-3eae5df9f497",{"Tags":542,"_uid":77,"title":535,"content":543,"component":518,"seoOgImage":962,"previewImage":966,"previewTitle":968,"relatedContent":969,"seoDescription":1131,"previewDescription":1131,"shortOutcomeDescription":1132},"container security, Kubernetes, cybersecurity",{"type":17,"content":544},[545,555,563,572,580,622,630,639,647,657,665,673,682,690,722,730,739,747,756,764,773,782,790,799,807,816,824,833,842,850,858,866,875,883,891,899,907,915,928,937,944,952],{"type":82,"attrs":546,"content":547},{"level":84,"textAlign":22},[548],{"text":549,"type":26,"marks":550},"Unprecedented speed, scalability, and development velocity are brought about by this evolution, but it also opens up new attack vectors and reveals serious security flaws that conventional network and perimeter-based controls cannot fix.",[551,554],{"type":29,"attrs":552},{"color":553},"#003B5C",{"type":92},{"type":20,"attrs":556,"content":557},{"textAlign":22},[558],{"text":559,"type":26,"marks":560},"Businesses must deal with the distinct and quickly changing security challenges posed by containerized, ephemeral, and distributed microservice workloads as they embrace the agility of cloud-native infrastructures. Xiid Terniion is a radically novel method designed specifically to protect these contemporary settings at the rate at which they change.",[561],{"type":29,"attrs":562},{"color":553},{"type":82,"attrs":564,"content":565},{"level":131,"textAlign":22},[566],{"text":567,"type":26,"marks":568},"Industry Challenge: The Modern Container Security Gap",[569,571],{"type":29,"attrs":570},{"color":138},{"type":92},{"type":20,"attrs":573,"content":574},{"textAlign":22},[575],{"text":576,"type":26,"marks":577},"Across sectors—whether finance, healthcare, manufacturing, or technology—operational environments are marked by:",[578],{"type":29,"attrs":579},{"color":553},{"type":149,"content":581},[582,592,602,612],{"type":152,"content":583},[584],{"type":20,"attrs":585,"content":586},{"textAlign":22},[587],{"text":588,"type":26,"marks":589},"Ephemeral Workloads: 70% of containers live less than 5 minutes, with attack windows often completing within 10 minutes",[590],{"type":29,"attrs":591},{"color":553},{"type":152,"content":593},[594],{"type":20,"attrs":595,"content":596},{"textAlign":22},[597],{"text":598,"type":26,"marks":599},"Constant Change & Scaling: Continuous deployments and updates introduce new workloads at breakneck speed, while auto-scaling sees containers rapidly spin up and down to meet demand.",[600],{"type":29,"attrs":601},{"color":553},{"type":152,"content":603},[604],{"type":20,"attrs":605,"content":606},{"textAlign":22},[607],{"text":608,"type":26,"marks":609},"IP Address Volatility: Containers are regularly restarted or moved, causing frequent IP changes that render static network policies and firewalls ineffective.",[610],{"type":29,"attrs":611},{"color":553},{"type":152,"content":613},[614],{"type":20,"attrs":615,"content":616},{"textAlign":22},[617],{"text":618,"type":26,"marks":619},"Orchestration & API Exposure: Control planes, such as Kubernetes APIs and registries, form high-value targets with elevated privileges and lateral movement risks.",[620],{"type":29,"attrs":621},{"color":553},{"type":20,"attrs":623,"content":624},{"textAlign":22},[625],{"text":626,"type":26,"marks":627},"These realities challenge established notions of perimeter defense, making it clear that legacy firewalls, static rules, and complex overlays (like service meshes) fail to keep pace with true container-driven operations. Container security must be as dynamic and granular as the environments it protects.",[628],{"type":29,"attrs":629},{"color":553},{"type":82,"attrs":631,"content":632},{"level":131,"textAlign":22},[633],{"text":634,"type":26,"marks":635},"The Xiid Solution: True Zero Trust Container Security with Terniion",[636,638],{"type":29,"attrs":637},{"color":138},{"type":92},{"type":20,"attrs":640,"content":641},{"textAlign":22},[642],{"text":643,"type":26,"marks":644},"Xiid Terniion was engineered to directly address these pervasive industry issues through several core innovations:",[645],{"type":29,"attrs":646},{"color":553},{"type":82,"attrs":648,"content":650},{"level":649,"textAlign":22},4,[651],{"text":652,"type":26,"marks":653},"Process-to-Process, Outbound-Only Security",[654,656],{"type":29,"attrs":655},{"color":553},{"type":92},{"type":20,"attrs":658,"content":659},{"textAlign":22},[660],{"text":661,"type":26,"marks":662},"By establishing process-level tunnels—instead of relying on IPs or hostnames—Terniion ensures every containerized process maintains an immutable, isolated, and identifable security boundary, regardless of how underlying infrastructure or IP addresses change.",[663],{"type":29,"attrs":664},{"color":553},{"type":20,"attrs":666,"content":667},{"textAlign":22},[668],{"text":669,"type":26,"marks":670},"All connections are outbound-only and triple-encrypted with multiple layers of end-to-end encryption, meaning containers and hosts never expose inbound ports or data to middlemen or attackers. This outbound architecture eliminates exposed attack surfaces and significantly reduces the risk of lateral movement within the cloud or data center.",[671],{"type":29,"attrs":672},{"color":553},{"type":82,"attrs":674,"content":675},{"level":649,"textAlign":22},[676],{"text":677,"type":26,"marks":678},"Quantum-Secure Triple Encryption",[679,681],{"type":29,"attrs":680},{"color":553},{"type":92},{"type":20,"attrs":683,"content":684},{"textAlign":22},[685],{"text":686,"type":26,"marks":687},"Terniion augments defense-in-depth with three distinct layers of encryption:",[688],{"type":29,"attrs":689},{"color":553},{"type":149,"content":691},[692,702,712],{"type":152,"content":693},[694],{"type":20,"attrs":695,"content":696},{"textAlign":22},[697],{"text":698,"type":26,"marks":699},"TLS 1.3 for outer-layer transport security",[700],{"type":29,"attrs":701},{"color":553},{"type":152,"content":703},[704],{"type":20,"attrs":705,"content":706},{"textAlign":22},[707],{"text":708,"type":26,"marks":709},"Kyber KEM and Dilithium digital signatures for post-quantum resilience",[710],{"type":29,"attrs":711},{"color":553},{"type":152,"content":713},[714],{"type":20,"attrs":715,"content":716},{"textAlign":22},[717],{"text":718,"type":26,"marks":719},"AES-256-GCM AEAD as the inner core",[720],{"type":29,"attrs":721},{"color":553},{"type":20,"attrs":723,"content":724},{"textAlign":22},[725],{"text":726,"type":26,"marks":727},"This allows organizations to future-proof sensitive data and operations even as quantum computing threats evolve.",[728],{"type":29,"attrs":729},{"color":553},{"type":82,"attrs":731,"content":732},{"level":649,"textAlign":22},[733],{"text":734,"type":26,"marks":735},"Automated, Profile-Driven Security with Profles",[736,738],{"type":29,"attrs":737},{"color":553},{"type":92},{"type":20,"attrs":740,"content":741},{"textAlign":22},[742],{"text":743,"type":26,"marks":744},"SealedTunnel Profiles make it possible to deploy fully-networked, pre-configured, and securely isolated containers with no manual intervention. Standardized, template-based mappings and bindings ensure that security is consistent and immediate for new workloads, allowing seamless horizontal scaling without security bottlenecks or manual interventions.",[745],{"type":29,"attrs":746},{"color":553},{"type":82,"attrs":748,"content":749},{"level":649,"textAlign":22},[750],{"text":751,"type":26,"marks":752},"Multi-Cloud, Multi-Pattern Support",[753,755],{"type":29,"attrs":754},{"color":553},{"type":92},{"type":20,"attrs":757,"content":758},{"textAlign":22},[759],{"text":760,"type":26,"marks":761},"With Kubernetes integration (including sidecar, daemonset, and gateway models), enterprises benefit from cloud-agnostic security that works seamlessly across AWS, Azure, Google Cloud, on-premises, and edge deployments.",[762],{"type":29,"attrs":763},{"color":553},{"type":82,"attrs":765,"content":766},{"level":649,"textAlign":22},[767],{"text":768,"type":26,"marks":769},"Use Cases Across the Modern Enterprise",[770,772],{"type":29,"attrs":771},{"color":553},{"type":92},{"type":20,"attrs":774,"content":775},{"textAlign":22},[776],{"text":777,"type":26,"marks":778},"Agile Microservices",[779,781],{"type":29,"attrs":780},{"color":553},{"type":92},{"type":20,"attrs":783,"content":784},{"textAlign":22},[785],{"text":786,"type":26,"marks":787},"Organizations supporting microservice architectures benefit from SealedTunnel’s process-to-process tunneling and microsegmentation, allowing secure horizontal scaling without IP or firewall reconfiguration delays and resilient, secure inter-service communication.",[788],{"type":29,"attrs":789},{"color":553},{"type":20,"attrs":791,"content":792},{"textAlign":22},[793],{"text":794,"type":26,"marks":795},"CI\u002FCD and Software Supply Chain Security",[796,798],{"type":29,"attrs":797},{"color":553},{"type":92},{"type":20,"attrs":800,"content":801},{"textAlign":22},[802],{"text":803,"type":26,"marks":804},"As CI\u002FCD pipelines become attack vectors, SealedTunnel delivers complete network isolation for build runners and code repositories. Outbound-only connections and zero required public IP exposure neutralize zero-day attacks and emerging threats.",[805],{"type":29,"attrs":806},{"color":553},{"type":20,"attrs":808,"content":809},{"textAlign":22},[810],{"text":811,"type":26,"marks":812},"Machine Learning, AI, IoT, and Edge Workloads",[813,815],{"type":29,"attrs":814},{"color":553},{"type":92},{"type":20,"attrs":817,"content":818},{"textAlign":22},[819],{"text":820,"type":26,"marks":821},"From large model delivery to constrained edge devices, SealedTunnel ensures all data transfers are triple-encrypted, resilient to unreliable networks, and securely isolated regardless of the underlying compute platform.",[822],{"type":29,"attrs":823},{"color":553},{"type":82,"attrs":825,"content":826},{"level":131,"textAlign":22},[827],{"text":828,"type":26,"marks":829},"Business Impact and ROI",[830,832],{"type":29,"attrs":831},{"color":138},{"type":92},{"type":82,"attrs":834,"content":835},{"level":649,"textAlign":22},[836],{"text":837,"type":26,"marks":838},"Security Risk Reduction",[839,841],{"type":29,"attrs":840},{"color":553},{"type":92},{"type":20,"attrs":843,"content":844},{"textAlign":22},[845],{"text":846,"type":26,"marks":847},"• Drastically reduced attack surface: No open inbound ports and immutable process boundaries.",[848],{"type":29,"attrs":849},{"color":553},{"type":20,"attrs":851,"content":852},{"textAlign":22},[853],{"text":854,"type":26,"marks":855},"• Breach containment: Lateral movement is prevented at the process level—not just at the endpoint.",[856],{"type":29,"attrs":857},{"color":553},{"type":20,"attrs":859,"content":860},{"textAlign":22},[861],{"text":862,"type":26,"marks":863},"• Compliance readiness: Automated, robust encryption and access controls facilitate PCI DSS, HIPAA, and SOC 2 alignment.",[864],{"type":29,"attrs":865},{"color":553},{"type":82,"attrs":867,"content":868},{"level":649,"textAlign":22},[869],{"text":870,"type":26,"marks":871},"Operational Effciency and Cost Optimization",[872,874],{"type":29,"attrs":873},{"color":553},{"type":92},{"type":20,"attrs":876,"content":877},{"textAlign":22},[878],{"text":879,"type":26,"marks":880},"• Streamlined deployment: Automated profile-driven configuration enables rapid environment provisioning and continuous deployment.",[881],{"type":29,"attrs":882},{"color":553},{"type":20,"attrs":884,"content":885},{"textAlign":22},[886],{"text":887,"type":26,"marks":888},"• Elastic scalability: Security scales seamlessly with application loads, without creating network configuration-related chokepoints or delays.",[889],{"type":29,"attrs":890},{"color":553},{"type":20,"attrs":892,"content":893},{"textAlign":22},[894],{"text":895,"type":26,"marks":896},"• Toolchain consolidation: SealedTunnel replaces multiple legacy tools, reducing licensing and management overhead.",[897],{"type":29,"attrs":898},{"color":553},{"type":82,"attrs":900,"content":901},{"level":131,"textAlign":22},[902],{"text":465,"type":26,"marks":903},[904,906],{"type":29,"attrs":905},{"color":138},{"type":92},{"type":20,"attrs":908,"content":909},{"textAlign":22},[910],{"text":911,"type":26,"marks":912},"Xiid’s platform is field-tested in hostile environments, penetration tested by the U.S. Air Force Research Laboratory, and has been granted an unconditional Authority to Operate by the U.S. Department of Defense, proving real-world resilience for critical and sensitive workloads.",[913],{"type":29,"attrs":914},{"color":553},{"type":20,"attrs":916,"content":917},{"textAlign":22},[918],{"text":919,"type":26,"marks":920},"Comparative Assessment",[921,923,927],{"type":29,"attrs":922},{"color":553},{"type":924,"attrs":925},"anchor",{"id":926},"yui_3_17_2_1_1784827017577_497",{"type":92},{"type":20,"attrs":929,"content":930},{"textAlign":22},[931],{"type":932,"attrs":933},"image",{"id":934,"alt":521,"src":935,"title":521,"source":521,"copyright":521,"meta_data":936},201268827202504,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F1292x771\u002Fa37ea88803\u002Fscreenshot_6-9-2025_153939_.jpeg",{},{"type":82,"attrs":938,"content":939},{"level":131,"textAlign":22},[940],{"text":490,"type":26,"marks":941},[942],{"type":29,"attrs":943},{"color":138},{"type":20,"attrs":945,"content":946},{"textAlign":22},[947],{"text":948,"type":26,"marks":949},"Only the process-to-process, outbound-only Terniion can keep pace with the operational realities of modern dynamic containerized architectures. Xiid’s platform provides the automation, quantum resilience, and integration needed to make security a force multiplier for DevSecOps—not a drag.",[950],{"type":29,"attrs":951},{"color":553},{"type":20,"attrs":953,"content":954},{"textAlign":22},[955,960],{"text":956,"type":26,"marks":957},"Organizations investing today in quantum-secure, process-isolated networking are well-positioned to thrive as the demand for speed, regulatory compliance, and security grows—across cloud, edge, and the inevitable quantum-powered future.",[958],{"type":29,"attrs":959},{"color":553},{"text":961,"type":26}," ",{"id":963,"alt":521,"name":521,"focus":521,"title":521,"source":521,"filename":964,"copyright":521,"fieldtype":523,"meta_data":965,"is_external_url":15},201325896601723,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F5292x3528\u002Fe014f32c26\u002Fgovernmental-hackers-exploiting-network-systems-high-tech-office.jpg",{},{"id":963,"alt":521,"name":521,"focus":521,"title":521,"source":521,"filename":964,"copyright":521,"fieldtype":523,"meta_data":967,"is_external_url":15},{},"Securing dynamic containerized environments Use Case | Xiid",[970],{"_uid":531,"variant":532,"resource":971,"component":1129,"background":1130},[972],{"name":973,"created_at":974,"published_at":975,"updated_at":976,"id":977,"uuid":978,"content":979,"slug":1119,"full_slug":1120,"sort_by_date":1121,"position":1122,"tag_list":1123,"is_startpage":15,"parent_id":1124,"meta_data":22,"group_id":1125,"first_published_at":1126,"release_id":22,"lang":39,"path":22,"alternates":1127,"default_full_slug":22,"translated_slugs":22,"_stopResolving":1128},"CI\u002FCD pipeline security: Human error is inevitable. Lateral movement isn't","2026-06-15T23:11:55.413Z","2026-07-27T21:04:49.739Z","2026-07-27T21:04:49.754Z",187906111156902,"d0949410-f184-41bd-88ee-b8a421a5f7ae",{"Tags":521,"_uid":980,"body":981,"title":982,"content":983,"component":1084,"seoOgImage":1085,"keyTakeaways":1089,"previewImage":1114,"previewTitle":982,"relatedContent":1116,"seoDescription":1117,"previewDescription":1118},"69a52ed9-008b-4441-a3c4-57b32d15254b",[],"CI\u002FCD pipeline security: Human error is inevitable. Lateral movement isn't.",{"type":17,"content":984},[985,990,997,1002,1007,1014,1023,1028,1035,1040,1045,1050,1057,1062,1067,1074,1079],{"type":20,"attrs":986,"content":987},{"textAlign":22},[988],{"text":989,"type":26},"The incident report always reads “human error\": a misconfigured runner, a committed token, an overpermissioned service account attached to a build job that didn’t need it. These mistakes happen at every company, regardless of maturity level, so the question isn’t whether they’ll happen to your team. The question is how your architecture lets those errors compound.",{"type":82,"attrs":991,"content":992},{"level":84,"textAlign":22},[993],{"text":994,"type":26,"marks":995},"A Compromised Runner Is a Beachhead",[996],{"type":92},{"type":20,"attrs":998,"content":999},{"textAlign":22},[1000],{"text":1001,"type":26},"When attackers gain access to a CI\u002FCD pipeline runner through a leaked token, a poisoned dependency, or a misconfigured environment variable, they don’t stop there. They enumerate everything reachable from that position, including artifact stores, secrets managers, container registries, staging environments, and sometimes even production databases. They look for credentials baked into the source code, its comments, and the documentation markup. They probe the subnet for services the runner was never supposed to touch but can, because no one restricted the network paths when it was originally provisioned.",{"type":20,"attrs":1003,"content":1004},{"textAlign":22},[1005],{"text":1006,"type":26},"That’s the blast radius problem in software delivery pipelines. A typical GitLab runner sitting on a shared subnet can reach the artifact store, the secrets vault, adjacent runners, and internal APIs all in the same network breath. The misconfiguration is the entry point, but the open network is the damage multiplier.",{"type":82,"attrs":1008,"content":1009},{"level":84,"textAlign":22},[1010],{"text":1011,"type":26,"marks":1012},"Why Least Privilege Alone Doesn’t Contain the Damage",[1013],{"type":92},{"type":20,"attrs":1015,"content":1016},{"textAlign":22},[1017,1021],{"text":1018,"type":26,"marks":1019},"T",[1020],{"type":92},{"text":1022,"type":26},"he standard DevSecOps response to blast radius is least-privilege configuration: tighten IAM policies, scope tokens to the minimum needed permissions, and rotate secrets on a schedule. While these are necessary controls, none of them solve the lateral movement problem.",{"type":20,"attrs":1024,"content":1025},{"textAlign":22},[1026],{"text":1027,"type":26},"Least privilege governs what a process is authorized to do. However, it has no effect on what’s network-reachable to a compromised process. A misconfigured IAM role is one mistake, but the runner can still attempt connections to adjacent services, scan for open ports, and exploit trust relationships baked into the subnet’s routing table. Authorization policy and network reachability operate on different layers, and closing the gap at the authorization layer leaves the network layer wide open.",{"type":82,"attrs":1029,"content":1030},{"level":84,"textAlign":22},[1031],{"text":1032,"type":26,"marks":1033},"Terniion Removes the Paths, Not Just the Permissions",[1034],{"type":92},{"type":20,"attrs":1036,"content":1037},{"textAlign":22},[1038],{"text":1039,"type":26},"Terniion approaches CI\u002FCD pipeline security from a different premise: instead of configuring what’s allowed to reach what, make every pipeline component non-addressable by default and grant reachability only where it’s explicitly required.",{"type":20,"attrs":1041,"content":1042},{"textAlign":22},[1043],{"text":1044,"type":26},"Terniion deploys lightweight STLink agents alongside protected pipeline components. Each STLink establishes outbound-only, process-to-process connections with triple-layer, quantum-resistant encryption. No inbound ports open. No public IPs. No routable addresses exposed on the subnet. A runner authorized to pull artifacts from a specific store does exactly that and nothing else. The network path to the secrets vault, to adjacent runners, and to staging simply doesn’t exist from that runner’s position. Probing the subnet returns nothing because there’s nothing addressable to probe.",{"type":20,"attrs":1046,"content":1047},{"textAlign":22},[1048],{"text":1049,"type":26},"This is the distinction between restricting what a compromised process can do versus eliminating what it can reach. The first approach relies on the perimeter holding. The second doesn’t need that assumption.",{"type":82,"attrs":1051,"content":1052},{"level":84,"textAlign":22},[1053],{"text":1054,"type":26,"marks":1055},"Blast Radius as a Design Parameter",[1056],{"type":92},{"type":20,"attrs":1058,"content":1059},{"textAlign":22},[1060],{"text":1061,"type":26},"Because Terniion works at the process level rather than the network level, the blast radius shrinks to whatever a specific process was authorized to reach—and nothing else. A build runner connected to the artifact store has exactly that: one tunnel, one destination, one authorized process on each end. There is no tunnel to the secrets manager, no tunnel to staging, no tunnel to production, because SealedTunnel never establishes connections that weren't explicitly configured. An attacker who compromises that runner can't pivot to other systems because the paths to those systems were never created in the first place.",{"type":20,"attrs":1063,"content":1064},{"textAlign":22},[1065],{"text":1066,"type":26},"Layered with Aclave credential-less authentication, which removes stored usernames, passwords, and long-lived certificates from the pipeline entirely, the architecture eliminates both the movement path and the credential that a compromised runner could carry to another system.",{"type":82,"attrs":1068,"content":1069},{"level":84,"textAlign":22},[1070],{"text":1071,"type":26,"marks":1072},"Error Prevention and Error Containment Are Different Problems ",[1073],{"type":92},{"type":20,"attrs":1075,"content":1076},{"textAlign":22},[1077],{"text":1078,"type":26},"Most pipeline security investment goes into preventing mistakes. Examples of this are secret scanning, pre-commit hooks, tighter code review, or security training. All of it matters, but none of it is a substitute for an architecture that limits what a mistake can become.",{"type":20,"attrs":1080,"content":1081},{"textAlign":22},[1082],{"text":1083,"type":26},"When the inevitable misconfiguration happens, the architecture either gives attackers a subnet to pivot across or it doesn’t. Terniion’s process-to-process tunneling and Zone-enforced segmentation make pipeline components non-addressable to anything outside their authorized communication scope. Your engineers don’t become less human. The blast just has nowhere left to go.","BlogPost",{"id":1086,"alt":521,"name":521,"focus":521,"title":521,"source":521,"filename":1087,"copyright":521,"fieldtype":523,"meta_data":1088,"is_external_url":15},201614295374915,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F6912x3888\u002Fd3bebd6fa6\u002Fpc-screens-server-hub-office-desk-showing-programming-software-close-up.jpg",{},{"type":17,"content":1090},[1091],{"type":149,"content":1092},[1093,1100,1107],{"type":152,"content":1094},[1095],{"type":20,"attrs":1096,"content":1097},{"textAlign":22},[1098],{"text":1099,"type":26},"Human error in CI\u002FCD pipelines—misconfigured credentials, leaked secrets, improper access—is inevitable, but lateral movement from those errors doesn't have to be.",{"type":152,"content":1101},[1102],{"type":20,"attrs":1103,"content":1104},{"textAlign":22},[1105],{"text":1106,"type":26},"Outbound-only, process-to-process architecture contains the blast radius: a compromised credential or node can't pivot to other systems.",{"type":152,"content":1108},[1109],{"type":20,"attrs":1110,"content":1111},{"textAlign":22},[1112],{"text":1113,"type":26},"Traditional CI\u002FCD security tools focus on detecting threats after access is granted; Terniion removes the exposure before the process starts.",{"id":1086,"alt":521,"name":521,"focus":521,"title":521,"source":521,"filename":1087,"copyright":521,"fieldtype":523,"meta_data":1115,"is_external_url":15},{},[],"When a CI\u002FCD runner gets compromised, the real damage comes from lateral movement — here's how Terniion's process-level isolation eliminates the pathways attackers need to pivot.","The incident report always reads \"human error\" - a misconfigured runner, a committed token, or an overpermissioned service account attached to a build job that didn't need it. ","cicd-pipeline-human-error-is-inevitable","blog\u002Fcicd-pipeline-human-error-is-inevitable","2026-04-15",50,[],193139877037850,"763d95bc-8eae-48f5-a95a-3b931b2fc331","2026-04-15T09:06:00.000Z",[],true,"ResourceFeatureCard","white","See how Xiid Terniion delivers quantum-secure, process-to-process protection for Kubernetes, CI\u002FCD, and multi-cloud containers—eliminating attack surfaces and streamlining security at scale.",{"type":17,"content":1133},[1134],{"type":20,"attrs":1135,"content":1136},{"textAlign":22},[1137],{"text":1138,"type":26,"marks":1139},"Organizations in a variety of industries are switching from static legacy systems to dynamic, containerized architectures driven by CI\u002FCD pipelines and Kubernetes.",[1140],{"type":29,"attrs":1141},{"color":1142},"#2CD5C4","securing-dynamic-containerized-environments","case-studies\u002Fsecuring-dynamic-containerized-environments",-10,[],188221605925663,"c1e17c84-7224-47c5-9d45-d675aec99328",[],"See how ConsentVault protects AI ingestion pipelines, genomic data lakes, eConsent records, and inference endpoints from breach using Terniion's non-addressable infrastructure and process-level isolation.","ConsentVault manages clinical genomic data and eConsent workflows that can't be remediated after compromise. See how Terniion makes their AI infrastructure architecturally unreachable and keeps it that way under HIPAA and EU GDPR.",{"type":17,"attrs":1153,"content":1154},{"backgroundColor":22},[1155],{"type":20,"attrs":1156,"content":1157},{"textAlign":22},[1158],{"text":1159,"type":26,"marks":1160},"Clinical AI is operating under a threat model that most security architectures were never designed to handle.",[1161],{"type":29,"attrs":1162},{"color":1142},"securing-the-ai-development-lifecycle","case-studies\u002Fsecuring-the-ai-development-lifecycle",20,[],"e66154ab-bab9-4574-ae3b-8b095c06a6f5",[],[1170,1672],{"name":535,"created_at":536,"published_at":537,"updated_at":538,"id":539,"uuid":540,"content":1171,"slug":1143,"full_slug":1144,"sort_by_date":22,"position":1145,"tag_list":1670,"is_startpage":15,"parent_id":1147,"meta_data":22,"group_id":1148,"first_published_at":537,"release_id":22,"lang":39,"path":22,"alternates":1671,"default_full_slug":22,"translated_slugs":22},{"Tags":542,"_uid":77,"title":535,"content":1172,"component":518,"seoOgImage":1539,"previewImage":1541,"previewTitle":968,"relatedContent":1543,"seoDescription":1131,"previewDescription":1131,"shortOutcomeDescription":1661},{"type":17,"content":1173},[1174,1182,1189,1197,1204,1242,1249,1257,1264,1272,1279,1286,1294,1301,1330,1337,1345,1352,1360,1367,1375,1383,1390,1398,1405,1413,1420,1428,1436,1443,1450,1457,1465,1472,1479,1486,1494,1501,1511,1517,1524,1531],{"type":82,"attrs":1175,"content":1176},{"level":84,"textAlign":22},[1177],{"text":549,"type":26,"marks":1178},[1179,1181],{"type":29,"attrs":1180},{"color":553},{"type":92},{"type":20,"attrs":1183,"content":1184},{"textAlign":22},[1185],{"text":559,"type":26,"marks":1186},[1187],{"type":29,"attrs":1188},{"color":553},{"type":82,"attrs":1190,"content":1191},{"level":131,"textAlign":22},[1192],{"text":567,"type":26,"marks":1193},[1194,1196],{"type":29,"attrs":1195},{"color":138},{"type":92},{"type":20,"attrs":1198,"content":1199},{"textAlign":22},[1200],{"text":576,"type":26,"marks":1201},[1202],{"type":29,"attrs":1203},{"color":553},{"type":149,"content":1205},[1206,1215,1224,1233],{"type":152,"content":1207},[1208],{"type":20,"attrs":1209,"content":1210},{"textAlign":22},[1211],{"text":588,"type":26,"marks":1212},[1213],{"type":29,"attrs":1214},{"color":553},{"type":152,"content":1216},[1217],{"type":20,"attrs":1218,"content":1219},{"textAlign":22},[1220],{"text":598,"type":26,"marks":1221},[1222],{"type":29,"attrs":1223},{"color":553},{"type":152,"content":1225},[1226],{"type":20,"attrs":1227,"content":1228},{"textAlign":22},[1229],{"text":608,"type":26,"marks":1230},[1231],{"type":29,"attrs":1232},{"color":553},{"type":152,"content":1234},[1235],{"type":20,"attrs":1236,"content":1237},{"textAlign":22},[1238],{"text":618,"type":26,"marks":1239},[1240],{"type":29,"attrs":1241},{"color":553},{"type":20,"attrs":1243,"content":1244},{"textAlign":22},[1245],{"text":626,"type":26,"marks":1246},[1247],{"type":29,"attrs":1248},{"color":553},{"type":82,"attrs":1250,"content":1251},{"level":131,"textAlign":22},[1252],{"text":634,"type":26,"marks":1253},[1254,1256],{"type":29,"attrs":1255},{"color":138},{"type":92},{"type":20,"attrs":1258,"content":1259},{"textAlign":22},[1260],{"text":643,"type":26,"marks":1261},[1262],{"type":29,"attrs":1263},{"color":553},{"type":82,"attrs":1265,"content":1266},{"level":649,"textAlign":22},[1267],{"text":652,"type":26,"marks":1268},[1269,1271],{"type":29,"attrs":1270},{"color":553},{"type":92},{"type":20,"attrs":1273,"content":1274},{"textAlign":22},[1275],{"text":661,"type":26,"marks":1276},[1277],{"type":29,"attrs":1278},{"color":553},{"type":20,"attrs":1280,"content":1281},{"textAlign":22},[1282],{"text":669,"type":26,"marks":1283},[1284],{"type":29,"attrs":1285},{"color":553},{"type":82,"attrs":1287,"content":1288},{"level":649,"textAlign":22},[1289],{"text":677,"type":26,"marks":1290},[1291,1293],{"type":29,"attrs":1292},{"color":553},{"type":92},{"type":20,"attrs":1295,"content":1296},{"textAlign":22},[1297],{"text":686,"type":26,"marks":1298},[1299],{"type":29,"attrs":1300},{"color":553},{"type":149,"content":1302},[1303,1312,1321],{"type":152,"content":1304},[1305],{"type":20,"attrs":1306,"content":1307},{"textAlign":22},[1308],{"text":698,"type":26,"marks":1309},[1310],{"type":29,"attrs":1311},{"color":553},{"type":152,"content":1313},[1314],{"type":20,"attrs":1315,"content":1316},{"textAlign":22},[1317],{"text":708,"type":26,"marks":1318},[1319],{"type":29,"attrs":1320},{"color":553},{"type":152,"content":1322},[1323],{"type":20,"attrs":1324,"content":1325},{"textAlign":22},[1326],{"text":718,"type":26,"marks":1327},[1328],{"type":29,"attrs":1329},{"color":553},{"type":20,"attrs":1331,"content":1332},{"textAlign":22},[1333],{"text":726,"type":26,"marks":1334},[1335],{"type":29,"attrs":1336},{"color":553},{"type":82,"attrs":1338,"content":1339},{"level":649,"textAlign":22},[1340],{"text":734,"type":26,"marks":1341},[1342,1344],{"type":29,"attrs":1343},{"color":553},{"type":92},{"type":20,"attrs":1346,"content":1347},{"textAlign":22},[1348],{"text":743,"type":26,"marks":1349},[1350],{"type":29,"attrs":1351},{"color":553},{"type":82,"attrs":1353,"content":1354},{"level":649,"textAlign":22},[1355],{"text":751,"type":26,"marks":1356},[1357,1359],{"type":29,"attrs":1358},{"color":553},{"type":92},{"type":20,"attrs":1361,"content":1362},{"textAlign":22},[1363],{"text":760,"type":26,"marks":1364},[1365],{"type":29,"attrs":1366},{"color":553},{"type":82,"attrs":1368,"content":1369},{"level":649,"textAlign":22},[1370],{"text":768,"type":26,"marks":1371},[1372,1374],{"type":29,"attrs":1373},{"color":553},{"type":92},{"type":20,"attrs":1376,"content":1377},{"textAlign":22},[1378],{"text":777,"type":26,"marks":1379},[1380,1382],{"type":29,"attrs":1381},{"color":553},{"type":92},{"type":20,"attrs":1384,"content":1385},{"textAlign":22},[1386],{"text":786,"type":26,"marks":1387},[1388],{"type":29,"attrs":1389},{"color":553},{"type":20,"attrs":1391,"content":1392},{"textAlign":22},[1393],{"text":794,"type":26,"marks":1394},[1395,1397],{"type":29,"attrs":1396},{"color":553},{"type":92},{"type":20,"attrs":1399,"content":1400},{"textAlign":22},[1401],{"text":803,"type":26,"marks":1402},[1403],{"type":29,"attrs":1404},{"color":553},{"type":20,"attrs":1406,"content":1407},{"textAlign":22},[1408],{"text":811,"type":26,"marks":1409},[1410,1412],{"type":29,"attrs":1411},{"color":553},{"type":92},{"type":20,"attrs":1414,"content":1415},{"textAlign":22},[1416],{"text":820,"type":26,"marks":1417},[1418],{"type":29,"attrs":1419},{"color":553},{"type":82,"attrs":1421,"content":1422},{"level":131,"textAlign":22},[1423],{"text":828,"type":26,"marks":1424},[1425,1427],{"type":29,"attrs":1426},{"color":138},{"type":92},{"type":82,"attrs":1429,"content":1430},{"level":649,"textAlign":22},[1431],{"text":837,"type":26,"marks":1432},[1433,1435],{"type":29,"attrs":1434},{"color":553},{"type":92},{"type":20,"attrs":1437,"content":1438},{"textAlign":22},[1439],{"text":846,"type":26,"marks":1440},[1441],{"type":29,"attrs":1442},{"color":553},{"type":20,"attrs":1444,"content":1445},{"textAlign":22},[1446],{"text":854,"type":26,"marks":1447},[1448],{"type":29,"attrs":1449},{"color":553},{"type":20,"attrs":1451,"content":1452},{"textAlign":22},[1453],{"text":862,"type":26,"marks":1454},[1455],{"type":29,"attrs":1456},{"color":553},{"type":82,"attrs":1458,"content":1459},{"level":649,"textAlign":22},[1460],{"text":870,"type":26,"marks":1461},[1462,1464],{"type":29,"attrs":1463},{"color":553},{"type":92},{"type":20,"attrs":1466,"content":1467},{"textAlign":22},[1468],{"text":879,"type":26,"marks":1469},[1470],{"type":29,"attrs":1471},{"color":553},{"type":20,"attrs":1473,"content":1474},{"textAlign":22},[1475],{"text":887,"type":26,"marks":1476},[1477],{"type":29,"attrs":1478},{"color":553},{"type":20,"attrs":1480,"content":1481},{"textAlign":22},[1482],{"text":895,"type":26,"marks":1483},[1484],{"type":29,"attrs":1485},{"color":553},{"type":82,"attrs":1487,"content":1488},{"level":131,"textAlign":22},[1489],{"text":465,"type":26,"marks":1490},[1491,1493],{"type":29,"attrs":1492},{"color":138},{"type":92},{"type":20,"attrs":1495,"content":1496},{"textAlign":22},[1497],{"text":911,"type":26,"marks":1498},[1499],{"type":29,"attrs":1500},{"color":553},{"type":20,"attrs":1502,"content":1503},{"textAlign":22},[1504],{"text":919,"type":26,"marks":1505},[1506,1508,1510],{"type":29,"attrs":1507},{"color":553},{"type":924,"attrs":1509},{"id":926},{"type":92},{"type":20,"attrs":1512,"content":1513},{"textAlign":22},[1514],{"type":932,"attrs":1515},{"id":934,"alt":521,"src":935,"title":521,"source":521,"copyright":521,"meta_data":1516},{},{"type":82,"attrs":1518,"content":1519},{"level":131,"textAlign":22},[1520],{"text":490,"type":26,"marks":1521},[1522],{"type":29,"attrs":1523},{"color":138},{"type":20,"attrs":1525,"content":1526},{"textAlign":22},[1527],{"text":948,"type":26,"marks":1528},[1529],{"type":29,"attrs":1530},{"color":553},{"type":20,"attrs":1532,"content":1533},{"textAlign":22},[1534,1538],{"text":956,"type":26,"marks":1535},[1536],{"type":29,"attrs":1537},{"color":553},{"text":961,"type":26},{"id":963,"alt":521,"name":521,"focus":521,"title":521,"source":521,"filename":964,"copyright":521,"fieldtype":523,"meta_data":1540,"is_external_url":15},{},{"id":963,"alt":521,"name":521,"focus":521,"title":521,"source":521,"filename":964,"copyright":521,"fieldtype":523,"meta_data":1542,"is_external_url":15},{},[1544],{"_uid":531,"variant":532,"resource":1545,"component":1129,"background":1130},[1546],{"name":973,"created_at":974,"published_at":975,"updated_at":976,"id":977,"uuid":978,"content":1547,"slug":1119,"full_slug":1120,"sort_by_date":1121,"position":1122,"tag_list":1659,"is_startpage":15,"parent_id":1124,"meta_data":22,"group_id":1125,"first_published_at":1126,"release_id":22,"lang":39,"path":22,"alternates":1660,"default_full_slug":22,"translated_slugs":22,"_stopResolving":1128},{"Tags":521,"_uid":980,"body":1548,"title":982,"content":1549,"component":1084,"seoOgImage":1632,"keyTakeaways":1634,"previewImage":1656,"previewTitle":982,"relatedContent":1658,"seoDescription":1117,"previewDescription":1118},[],{"type":17,"content":1550},[1551,1555,1561,1565,1569,1575,1582,1586,1592,1596,1600,1604,1610,1614,1618,1624,1628],{"type":20,"attrs":1552,"content":1553},{"textAlign":22},[1554],{"text":989,"type":26},{"type":82,"attrs":1556,"content":1557},{"level":84,"textAlign":22},[1558],{"text":994,"type":26,"marks":1559},[1560],{"type":92},{"type":20,"attrs":1562,"content":1563},{"textAlign":22},[1564],{"text":1001,"type":26},{"type":20,"attrs":1566,"content":1567},{"textAlign":22},[1568],{"text":1006,"type":26},{"type":82,"attrs":1570,"content":1571},{"level":84,"textAlign":22},[1572],{"text":1011,"type":26,"marks":1573},[1574],{"type":92},{"type":20,"attrs":1576,"content":1577},{"textAlign":22},[1578,1581],{"text":1018,"type":26,"marks":1579},[1580],{"type":92},{"text":1022,"type":26},{"type":20,"attrs":1583,"content":1584},{"textAlign":22},[1585],{"text":1027,"type":26},{"type":82,"attrs":1587,"content":1588},{"level":84,"textAlign":22},[1589],{"text":1032,"type":26,"marks":1590},[1591],{"type":92},{"type":20,"attrs":1593,"content":1594},{"textAlign":22},[1595],{"text":1039,"type":26},{"type":20,"attrs":1597,"content":1598},{"textAlign":22},[1599],{"text":1044,"type":26},{"type":20,"attrs":1601,"content":1602},{"textAlign":22},[1603],{"text":1049,"type":26},{"type":82,"attrs":1605,"content":1606},{"level":84,"textAlign":22},[1607],{"text":1054,"type":26,"marks":1608},[1609],{"type":92},{"type":20,"attrs":1611,"content":1612},{"textAlign":22},[1613],{"text":1061,"type":26},{"type":20,"attrs":1615,"content":1616},{"textAlign":22},[1617],{"text":1066,"type":26},{"type":82,"attrs":1619,"content":1620},{"level":84,"textAlign":22},[1621],{"text":1071,"type":26,"marks":1622},[1623],{"type":92},{"type":20,"attrs":1625,"content":1626},{"textAlign":22},[1627],{"text":1078,"type":26},{"type":20,"attrs":1629,"content":1630},{"textAlign":22},[1631],{"text":1083,"type":26},{"id":1086,"alt":521,"name":521,"focus":521,"title":521,"source":521,"filename":1087,"copyright":521,"fieldtype":523,"meta_data":1633,"is_external_url":15},{},{"type":17,"content":1635},[1636],{"type":149,"content":1637},[1638,1644,1650],{"type":152,"content":1639},[1640],{"type":20,"attrs":1641,"content":1642},{"textAlign":22},[1643],{"text":1099,"type":26},{"type":152,"content":1645},[1646],{"type":20,"attrs":1647,"content":1648},{"textAlign":22},[1649],{"text":1106,"type":26},{"type":152,"content":1651},[1652],{"type":20,"attrs":1653,"content":1654},{"textAlign":22},[1655],{"text":1113,"type":26},{"id":1086,"alt":521,"name":521,"focus":521,"title":521,"source":521,"filename":1087,"copyright":521,"fieldtype":523,"meta_data":1657,"is_external_url":15},{},[],[],[],{"type":17,"content":1662},[1663],{"type":20,"attrs":1664,"content":1665},{"textAlign":22},[1666],{"text":1138,"type":26,"marks":1667},[1668],{"type":29,"attrs":1669},{"color":1142},[],[],{"name":973,"created_at":974,"published_at":975,"updated_at":976,"id":977,"uuid":978,"content":1673,"slug":1119,"full_slug":1120,"sort_by_date":1121,"position":1122,"tag_list":1785,"is_startpage":15,"parent_id":1124,"meta_data":22,"group_id":1125,"first_published_at":1126,"release_id":22,"lang":39,"path":22,"alternates":1786,"default_full_slug":22,"translated_slugs":22},{"Tags":521,"_uid":980,"body":1674,"title":982,"content":1675,"component":1084,"seoOgImage":1758,"keyTakeaways":1760,"previewImage":1782,"previewTitle":982,"relatedContent":1784,"seoDescription":1117,"previewDescription":1118},[],{"type":17,"content":1676},[1677,1681,1687,1691,1695,1701,1708,1712,1718,1722,1726,1730,1736,1740,1744,1750,1754],{"type":20,"attrs":1678,"content":1679},{"textAlign":22},[1680],{"text":989,"type":26},{"type":82,"attrs":1682,"content":1683},{"level":84,"textAlign":22},[1684],{"text":994,"type":26,"marks":1685},[1686],{"type":92},{"type":20,"attrs":1688,"content":1689},{"textAlign":22},[1690],{"text":1001,"type":26},{"type":20,"attrs":1692,"content":1693},{"textAlign":22},[1694],{"text":1006,"type":26},{"type":82,"attrs":1696,"content":1697},{"level":84,"textAlign":22},[1698],{"text":1011,"type":26,"marks":1699},[1700],{"type":92},{"type":20,"attrs":1702,"content":1703},{"textAlign":22},[1704,1707],{"text":1018,"type":26,"marks":1705},[1706],{"type":92},{"text":1022,"type":26},{"type":20,"attrs":1709,"content":1710},{"textAlign":22},[1711],{"text":1027,"type":26},{"type":82,"attrs":1713,"content":1714},{"level":84,"textAlign":22},[1715],{"text":1032,"type":26,"marks":1716},[1717],{"type":92},{"type":20,"attrs":1719,"content":1720},{"textAlign":22},[1721],{"text":1039,"type":26},{"type":20,"attrs":1723,"content":1724},{"textAlign":22},[1725],{"text":1044,"type":26},{"type":20,"attrs":1727,"content":1728},{"textAlign":22},[1729],{"text":1049,"type":26},{"type":82,"attrs":1731,"content":1732},{"level":84,"textAlign":22},[1733],{"text":1054,"type":26,"marks":1734},[1735],{"type":92},{"type":20,"attrs":1737,"content":1738},{"textAlign":22},[1739],{"text":1061,"type":26},{"type":20,"attrs":1741,"content":1742},{"textAlign":22},[1743],{"text":1066,"type":26},{"type":82,"attrs":1745,"content":1746},{"level":84,"textAlign":22},[1747],{"text":1071,"type":26,"marks":1748},[1749],{"type":92},{"type":20,"attrs":1751,"content":1752},{"textAlign":22},[1753],{"text":1078,"type":26},{"type":20,"attrs":1755,"content":1756},{"textAlign":22},[1757],{"text":1083,"type":26},{"id":1086,"alt":521,"name":521,"focus":521,"title":521,"source":521,"filename":1087,"copyright":521,"fieldtype":523,"meta_data":1759,"is_external_url":15},{},{"type":17,"content":1761},[1762],{"type":149,"content":1763},[1764,1770,1776],{"type":152,"content":1765},[1766],{"type":20,"attrs":1767,"content":1768},{"textAlign":22},[1769],{"text":1099,"type":26},{"type":152,"content":1771},[1772],{"type":20,"attrs":1773,"content":1774},{"textAlign":22},[1775],{"text":1106,"type":26},{"type":152,"content":1777},[1778],{"type":20,"attrs":1779,"content":1780},{"textAlign":22},[1781],{"text":1113,"type":26},{"id":1086,"alt":521,"name":521,"focus":521,"title":521,"source":521,"filename":1087,"copyright":521,"fieldtype":523,"meta_data":1783,"is_external_url":15},{},[],[],[],[],{"cache-control":46,"connection":47,"content-encoding":1789,"content-type":49,"date":1790,"etag":1791,"referrer-policy":52,"sb-be-version":53,"server":54,"transfer-encoding":1792,"vary":1793,"via":1794,"x-amz-cf-id":1795,"x-amz-cf-pop":58,"x-cache":59,"x-content-type-options":60,"x-frame-options":61,"x-permitted-cross-domain-policies":62,"x-request-id":1796,"x-runtime":1797,"x-xss-protection":65},"gzip","Thu, 13 Aug 2026 21:02:23 GMT","W\u002F\"ead9e9d660b63f570dd750219c66db68\"","chunked","Origin,Accept-Encoding","1.1 32a8b37046729bc3f47a204680708ef4.cloudfront.net (CloudFront)","nmB-0RhHS9toARBJrSupGip2nbpfNrTZxnurrGW1y6pMqKeZ9zodJA==","d7ed0cad-f84a-4722-a1f8-94df4f71f1ce","0.031337",1786654943515]