A DevSecOps checklist for AI-powered applications
Model artifacts, prompts, and eval data widen the attack surface of a modern app. A pragmatic set of controls — secrets, supply chain, and guardrails — you can adopt without slowing the team down.
Written by the engineers and researchers who ship the work — practical guides, honest postmortems, and architectural deep-dives from real customer engagements.
What actually matters when you take RAG from a prototype to something you can put in front of users — chunking, evaluation, and the failure modes that only show up in production.
insight / building-production-rag
AI
Filter by topic — or scan the latest, the team is shipping new pieces every couple of weeks.
Model artifacts, prompts, and eval data widen the attack surface of a modern app. A pragmatic set of controls — secrets, supply chain, and guardrails — you can adopt without slowing the team down.
Most rule-based automation is a good candidate for an agentic upgrade. How to identify the right workflows, scope the move, and keep a human in the loop where it counts.