research series
AI Interaction Data Fabric Insights
Tenant-Wide AI Vendor Grant · Regulated-Data Exposure Scoped
A permanent AI vendor grant runs through a shared account no human owns, scoped to the 61 labelled files it actually reached.
Reading the MCP Tool Boundary
A poisoned MCP tool sends credentials inside an agent session, caught at the gateway boundary that reads and refuses the call.
Insider Exfiltration During Notice · Regulated-Data Exposure
A departing engineer moves customer records into a personal AI account at 73 times the normal volume, sized before the badge goes inactive.
A Teardown of the Drift OAuth Supply-Chain Compromise
Stolen vendor OAuth tokens exported CRM records full of credentials, surfaced as a dated, scoped finding rather than a two-week wait.
Unauthorized ChatGPT Detection · Financial Data Upload Prevention
An unsanctioned AI assistant used inside finance leaves traces across four sources that read as exposure only once correlated together.
Risk-Based Prioritization: Quantifying AI Risk in Financial Terms
Financial quantification turns qualitative assessment findings into a remediation roadmap ranked by risk reduced per dollar spent.
Monitor, Educate, and Enforce AI Policy at the Browser
Browser-level enforcement covers the interaction layer that endpoint and network tools miss, stopping risky prompts before submission.
Building a Real-Time AI Inventory
Continuous discovery replaces manual tracking, surfacing every sanctioned and shadow AI asset as soon as it appears.
Monitoring AI Agent Behavior Across the Enterprise
Kovrr's connected telemetry surfaces rogue AI agents across the enterprise and attributes every action to a named user.
Get every issue as it publishes
One email per issue, no other mail. Unsubscribe at any time.





