All stacks

AI product team

A product and platform team building generative-AI applications or agents with access to internal data and tools, supported by security, cloud, data, and governance partners.

A reference overlay for an AI product: strong workload identity, AI discovery and governance, adversarial testing, runtime guardrails, data-loss controls, centralized telemetry, and recoverable supporting systems. It complements rather than replaces the organization's baseline security stack.

By Updated

The stack, layer by layer

All 10 defense layers, in order — what this team chose, why, and what they left for later.

  1. 01

    Identity & Access

    Microsoft Entra IDMicrosoftFreemium

    AI applications and agents need accountable workload identities and conditional access before they receive model, data, or tool permissions; Entra provides that identity boundary in a Microsoft-centered environment.

  2. 02

    Endpoint Protection

    Not covered

    No endpoint protection selected — malicious activity on laptops and servers may go undetected.

  3. 03

    Network Security

    Not covered

    No network security selected — visibility and control over network traffic will be limited.

  4. 04

    Email Security

    Not covered

    No email security selected — phishing and malicious email remain common initial-access paths.

  5. 05

    Cloud Security

    Not covered

    No cloud security selected — exposed services, weak permissions, and configuration mistakes can go unnoticed.

  6. 06

    Application Security

    garakCommunity projectFree

    A free, repeatable command-line probe suite gives engineers a practical first regression layer for prompt injection, data leakage, jailbreaks, and other generative-AI failure modes.

    NeMo GuardrailsCommunity projectFree

    Programmable input, retrieval, execution, and output rails let the application enforce its own policy around model interactions and agent tool use instead of trusting model behavior alone.

  7. 07

    Data Protection

    Microsoft Purview Data Loss PreventionMicrosoft$$

    AI-specific controls still need an enterprise data policy behind them; Purview gives the team shared sensitive-data definitions and loss-prevention controls across the Microsoft information estate.

  8. 08

    Detection & Response

    Microsoft SentinelMicrosoft$$

    AI runtime and application events need to join identity, cloud, endpoint, and data telemetry in the existing incident workflow so the team can investigate abuse as part of the wider environment.

  9. 09

    Resilience & Recovery

    Veeam Data PlatformVeeam Software$$$

    Models are only one dependency: the application, retrieval stores, configuration, and supporting workloads still need immutable backups and tested recovery from destructive incidents.

  10. 10

    Compliance & Awareness

    HiddenLayer AI Security PlatformHiddenLayer$$$

    Discovery, ownership, posture, and model lineage create the inventory an AI product team needs before it can apply policy or prove that security reviews cover the systems actually in production.

Search Cyber Tool Stack

Jump to any tool, vendor, category, or glossary term.