[API Security & Data Protection Blog]

Guides, best practices, and product updates on securing API traffic, detecting sensitive data, and staying compliant.

Security

Restrict Which Tools Your AI Agents Can Call

Unsupervised agents will call any tool you hand them. Grepture's new tool-restriction rule enforces an allowlist at the gateway — before the model ever sees the tool.

Ben @ Grepture

Read more

Your vector store is a permanent PII leak

Embedding raw user input into a vector store is a quiet, permanent data leak — and unlike chat logs, you can't selectively scrub it. Here's how to fix it before you have to.

Security

OpenAI Privacy Filter: A New PII Model You Can Run Locally

OpenAI released Privacy Filter, an open-weight 1.5B-parameter MoE model for PII redaction. Here's what it detects, how it compares, and where it fits in a real pipeline.

Security

Securing MCP Connections Through Your AI Gateway

MCP gives AI agents access to your tools and data. Here's how to monitor, inspect, and block malicious MCP traffic at the gateway layer.

Security

Best Open Source Models for PII Redaction

Indirect Prompt Injection: The Attack That Hides in Your Data

Your LLM Observability Tool Is Logging PII — Here's How to Fix It

How to Secure Your RAG Pipeline: Preventing Data Leaks in Retrieval-Augmented Generation

Why Your AI Agents Are Leaking Data (And How to Stop Them)

How to Prevent Sensitive Data Leaks in LLM API Calls

Prompt Injection Prevention for Production LLM Apps

PII Detection Best Practices for AI Pipelines