Keeping Secrets Out of Prompts
People paste passwords, keys and customer data into AI tools all the time, usually for perfectly good reasons. Here's why G8KEPR redacts that stuff before it ever leaves.
Building G8KEPR · Note 13 ↗The G8KEPR notebook
Notes and updates on G8KEPR.
People paste passwords, keys and customer data into AI tools all the time, usually for perfectly good reasons. Here's why G8KEPR redacts that stuff before it ever leaves.
Building G8KEPR · Note 13 ↗Runaway agents, retry loops and sudden spend spikes can turn an AI feature into a very expensive surprise. Here's why G8KEPR treats cost as a security problem.
Building G8KEPR · Note 14 ↗How G8KEPR's AI Gateway routes requests across many model providers, what circuit breakers and bring-your-own-key mean, and why one checkpoint beats security bolted onto every app.
Building G8KEPR · Note 15 ↗Some of the worst AI attacks are made of steps that each look harmless. Here's the lethal trifecta idea, and why G8KEPR's correlation engine looks across all four pillars at once.
Building G8KEPR · Note 16 ↗What agent hijacking and memory poisoning are, why agents raise the stakes, and what G8KEPR's MCP-side controls (tool permissions, session tracking, rug-pull detection) are there for.
Building G8KEPR · Note 17 ↗A security tool sees your most sensitive traffic, so where it sends that traffic matters. The trust argument behind keeping G8KEPR entirely inside your own infrastructure.
Building G8KEPR · Note 18 ↗G8KEPR 1.0 shipped with an independent pentest result of 0 critical, 0 high and 3 medium findings, and the company blog publishes red-team runs too. Here's why a security product should show its homework.
Building G8KEPR · Note 19 ↗G8KEPR went GA on April 14, 2026 and reached v1.5 by May 9. A walk through that stretch of the public changelog, and what I think a changelog is actually for.
Building G8KEPR · Note 20 ↗Every G8KEPR task list runs from "P0 — Blocks belief/purchase" down to "P4 — Polish". Why belief is the right word for a security product, and how it keeps a solo founder honest.
Building G8KEPR · Note 21 ↗The plan, not yet shipped, for a free MCP security CLI scanner: why I'd give a tool away, and the questions it's meant to help people running MCP servers answer.
Building G8KEPR · Note 22 ↗G8KEPR is a layer. It doesn't replace secure code, least-privilege tool design or the API gateway you already run. An honest look at where a runtime AI security layer fits and where it doesn't.
Building G8KEPR · Note 23 ↗