2AM Security
Subscribe
Sign in
Home
Notes
Archive
About
Latest
Top
Discussions
The Six Pillars of a Secure Agent Harness
Principles of Zero Custody. Six things the AI loop must not hold
Aug 12
•
Srajan Gupta
2
July 2026
From Zero Trust to Zero Custody
Zero Trust taught us to verify every actor. Zero Custody asks the harder question: why is that actor holding anything worth stealing?
Jul 27
•
Srajan Gupta
2
May 2026
The Graph Isn’t Enough for AI D&R
We’ve been building security graphs for traditional telemetry for years. Doing the same thing for AI agents is necessary, but it misses the hard part.
May 26
•
Srajan Gupta
2
1
1
April 2026
Where is My agent.lock file?
We pin every package to a hash. We let AI agents run with whatever they want.
Apr 15
•
Srajan Gupta
5
2
1
March 2026
The Trust Inversion: From Browser as OS to AI IDE as OS
How AI coding agents broke every assumption in application security
Mar 10
•
Srajan Gupta
3
December 2025
The Security PM Gap
Security Product Management Needs Its Own Playbook
Dec 19, 2025
•
Srajan Gupta
7
2
November 2025
We’re Not Coding Anymore, We’re Maintaining Coherence
Breaking the Illusion That AI Makes Development Easier
Nov 10, 2025
•
Srajan Gupta
5
1
May 2025
Security Is Just Engineering Tech Debt (And That's a Good Thing)
Breaking the Illusion That Security Is Anything But Software Quality
May 15, 2025
•
Srajan Gupta
15
3
4
April 2025
Threat Modeling GitHub - How vulnerable-by-design Github is?
Understanding the Security Debt Baked Into GitHub’s Design
Apr 9, 2025
•
Srajan Gupta
8
1
February 2025
Why is everyone selling Compliance?
Dissecting Security Sales Call
Feb 26, 2025
•
Srajan Gupta
2
3
January 2025
Security Anti-Patterns in the AI Era
Systemic mistakes masquerading as “practical solutions"
Jan 2, 2025
•
Srajan Gupta
3
1
November 2024
Paved Roads? Secure-by-Design?? More Buzzwords???
Is This the Key to Scaling Security?
Nov 11, 2024
•
Srajan Gupta
13
2
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts