Blackbead Blog

Field notes from the
AI security frontline.

How non-human identity is rewriting IAM. Why prompt injection beats your WAF. What the DPDP audit trail actually looks like when your agents make the decisions. Written by the engineers shipping it.

Topics All Agent identity Prompt injection Compliance Architecture LLM design

Latest from the team

Threat
May 6, 2026 · 9 min read

Prompt injection in 2026: indirect, multi-step, and through your trusted tools

The textbook prompt-injection prompt is a 2023 problem. The 2026 version arrives via a calendar invite, traverses three agents, and ends with your SaaS export running through a payload your IAM trusted.

Read more →
Compliance
Apr 28, 2026 · 8 min read

What the DPDP audit trail looks like when agents make the decisions

India's DPDP Act treats agents the same as humans for purposes of decisioning and consent. We walked a real BFSI auditor through a Blackbead trail. Here's the field they always ask for first — and the one you never thought to log.

Read more →
Architecture
Apr 21, 2026 · 11 min read

Agent mesh architecture: the A2A event bus we ship to BFSI

Why we moved away from a star topology, what AgentCop catches in production, and the four invariants we enforce on every agent-to-agent message — even when both ends are first-party.

Read more →
LLM design
Apr 14, 2026 · 10 min read

Guardrails and evals: a working stack for LLM features that ship

The eval pipeline we wired around our own agents. What we measure pre-deploy, what we measure in production, and the three regressions we caught last month that static tests would have missed.

Read more →
Case study
Apr 7, 2026 · 7 min read

Real-time fraud scoring inside a SWIFT MT103 hop

What it takes to put a model on the payment rail without missing the SLA. The signals we run, the latency budget we keep, and the explainability the bank's risk team actually reads.

Read more →
Product
Mar 31, 2026 · 6 min read

Jarvis: a personal security advisor for every role on the SOC floor

Why one chatbot doesn't fit a SOC analyst, threat hunter, security engineer, architect, and CISO. Five personas, one product — and the prompts and memory model behind each.

Read more →

One field-tested note. Every Tuesday.

What we shipped, what broke, what we learned. Written for security teams running real workloads, not for the recap deck.