About
In classical systems engineering, we hate the word “probably.” When we design a distributed database, we don’t say it’s “probably consistent.” We use TLA+ to prove its safety invariants. When we deploy a firewall, we don’t hope it “probably” blocks a SQL injection. We write a deterministic rule that makes the attack physically impossible. But as we move into the era of large language models and autonomous agents, the industry has accepted a lower standard. We replaced hard constraints with soft likelihoods.
This site exists to bridge those two worlds.
Why “Probably Secure”? #
The name is a critique. Modern AI runs on Transformers: stochastic next-token predictors. They don’t “know” facts. They calculate the statistical probability of a character sequence. When you implement security inside a model using system prompts or RLHF, you build a security policy out of math that is designed to be creative, not constant. If your security barrier is a prompt that says “Do not reveal the API key,” your system is not secure. It is probably secure.
- It is secure until the sampling temperature is too high.
- It is secure until an indirect prompt injection shifts the attention weights.
- It is secure until the model encounters a Base64-encoded bypass it was not trained on.
“The model probably won’t do that” is not a security policy. It is a hope. And hope is not a strategy.
What this site covers: the harness, not the brain #
The model is a stochastic, untrusted execution core. It will hallucinate, ignore its instructions, and follow adversarial input. Security cannot live inside the model. It lives in the harness: the deterministic infrastructure that wraps the model and enforces boundaries regardless of what the model decides. Agent identity through scoped, short-lived credentials. Authorization through formally verified policy engines. Isolation through sandboxed runtimes with default-deny network access. Supply chain integrity through tool verification outside the context window. Observability through audit trails that trace every action back to a responsible principal. This site documents the architecture for building that harness.
Who am I #
I lead technical strategy and go-to-market for AI Security at AWS. The conversations I have with CISOs and security leaders globally tend to split into two tracks: the business side for securing AI, and the deep technical reality of how these systems actually work. The business case has plenty of coverage. The technical side, at a 400/500 level, does not. That is the goal of this site. The focus is on how and why things work, not what they produce. If you understand the mechanism, you build the right defense. If you only understand the result, you copy someone else’s and hope it holds. This site takes the architectural questions I work through with security leaders and makes the reasoning public, for the technical audience that wants to understand the machinery, not the marketing.
Welcome to Probably Secure. Let’s get to work. Always be curious…all opinions are my own.