↓ Skip to main content

Security Cloud AI

INDEPENDENT AI SECURITY RESEARCH

Securing AI Agents. Exploring Zero Trust. Building What’s Next.
#

I’m Bryan Mack, an enterprise technology professional exploring the intersection of artificial intelligence, cybersecurity, and enterprise architecture.

Security Cloud AI is where I document my hands-on research into securing AI agents, large language models, Model Context Protocol (MCP) integrations, and the infrastructure that supports enterprise AI.

My focus is on understanding real security risks, testing practical controls, and translating technical findings into meaningful enterprise security strategies.


What I’m Working On
#

AI Agent and MCP Security
#

Exploring how AI agents interact with tools, APIs, external data, and enterprise systems. Areas of investigation include prompt injection, MCP tool poisoning, excessive permissions, agent identities, and trust boundaries.

Local AI and Model Infrastructure
#

Experimenting with local LLM deployment, model performance, orchestration, and routing between local and cloud-hosted AI models.

Zero Trust for AI
#

Designing segmented infrastructure and investigating how identity, least privilege, policy enforcement, and security monitoring apply to AI workloads and autonomous agents.


Technologies in My Lab
#

Currently deployed or being configured:

  • AI models: Ollama, Qwen3, local LLM inference
  • AI interfaces: Open WebUI
  • Application infrastructure: Docker, Linux, Python, REST APIs
  • Virtualization: Proxmox VE
  • Operating systems: Ubuntu Server, Windows 11
  • Networking and security: Fortinet FortiGate, UniFi networking, VLAN segmentation
  • Web infrastructure: Nginx, Cloudflare Tunnel, Cloudflare Zero Trust
  • Development: Git, PowerShell, Hugo

Planned Research and Lab Expansion
#

  • Agent orchestration: TrueForge and model-routing frameworks
  • Agent identity: Keycloak, OAuth 2.0, OpenID Connect, service identities
  • AI integration security: MCP servers, tool authorization, API gateways
  • Data services: PostgreSQL, vector databases, retrieval-augmented generation (RAG)
  • Monitoring and detection: Wazuh, Suricata, Zeek, centralized logging
  • Infrastructure: Expanded Proxmox environment and 10Gb networking
  • Public research assistant: A restricted AI agent answering questions about published research

These projects are evolving as I build, test, and document the environment.


Research Direction
#

My current areas of interest include:

  • Securing autonomous AI agents and MCP integrations
  • Zero Trust architecture for AI workloads
  • Identity and authorization for non-human actors
  • Prompt injection and tool misuse
  • RAG security and sensitive data exposure
  • Enterprise AI governance and observability
  • Secure hybrid local/cloud model architectures

As experiments progress, I’ll publish technical write-ups, architecture diagrams, security findings, and practical recommendations.


Connect
#

I’m always interested in exchanging ideas with security architects, AI practitioners, enterprise technology leaders, and organizations exploring secure AI adoption.

Email: [email protected]

LinkedIn: linkedin.com/in/bryanmack


Independent research and personal perspectives. Content does not represent the views or positions of any current or former employer.