Skip to main content

categories

Large Language Models (LLMs)

Browse Pomerium articles in the Large Language Models (LLMs) category.

Topic archive

Resources Categorized: Large Language Models (LLMs)

The OWASP Top 10 for LLMs and How to Defend Against Them
blog posts

The OWASP Top 10 for LLMs and How to Defend Against Them

TL;DR — The OWASP Top 10 for Large Language Model (LLM) applications highlights prompt injection, insecure output handling, and data exposure as critical risks. This guide walks through the Top 10 and shows where Zero Trust access controls, starting free with Pomerium Zero , are most effective: LLM01 Prompt Injection and LLM02 Sensitive Information Disclosure.

Why the Managed Context Protocol (MCP) Spec Still Leaves Gaping Security Holes
blog posts

Why the Managed Context Protocol (MCP) Spec Still Leaves Gaping Security Holes

TL;DR — MCP gives AI agents a shared way to invoke tools and complete tasks. But the spec lacks core security features. There is no built-in authorization, no identity enforcement, and no way to apply context-aware policy. Teams relying on reference servers are exposing internal APIs without guardrails. Pomerium applies Zero Trust controls to every request, adding identity, context, and policy enforcement at Layer 7.

Your Employees Are Already Dumping Company Data to LLMs (Here’s What To Do About It)
blog posts

Your Employees Are Already Dumping Company Data to LLMs (Here’s What To Do About It)

It's happening right now, in your organization. That senior developer just pasted your global auth tokens into ChatGPT to debug a tricky race condition. Your data analyst uploaded last quarter's customer churn data to Claude to help write their board presentation. Your product manager is feeding competitive analysis docs to Gemini to brainstorm feature ideas.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo