<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Topics on Pawan Khandavilli</title><link>https://pawankhandavilli.com/topics/</link><description>Recent content in Topics on Pawan Khandavilli</description><generator>Hugo -- 0.165.0</generator><language>en-US</language><atom:link href="https://pawankhandavilli.com/topics/index.xml" rel="self" type="application/rss+xml"/><item><title>Agent and MCP Security</title><link>https://pawankhandavilli.com/topics/agent-security/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://pawankhandavilli.com/topics/agent-security/</guid><description>Identity, delegation, tool permissions, and the trust boundaries behind autonomous AI systems.</description><content:encoded><![CDATA[<p>AI agents turn language into actions. That makes identity, delegated authority, tool permissions, and execution integrity part of the security boundary—not implementation details.</p>
<h2 id="start-here">Start here</h2>
<ol>
<li><a href="/posts/trust-is-the-next-bottleneck/">Trust Is the Next Bottleneck</a> explains why authorization alone cannot establish that an agent is running the expected code.</li>
<li><a href="/posts/ai-agents-have-an-identity-crisis-and-oauth-alone-will-not-fix-it/">AI Agents Have an Identity Crisis</a> examines verifiable delegation across multi-agent workflows.</li>
<li><a href="/posts/mcp-is-a-capability-system-treat-it-like-one/">MCP Is a Capability System</a> provides the practical permission model.</li>
<li><a href="/posts/mcp-security-why-ai-tool-servers-need-hardware-isolation/">Hardening MCP Servers with Confidential Computing</a> addresses the infrastructure trust boundary around tool credentials.</li>
<li><a href="/posts/googles-ap2-protocol-building-trust-in-autonomous-transactions/">Google&rsquo;s AP2 Protocol</a> applies these ideas to agent-initiated commerce.</li>
</ol>
<p>Together, these essays describe a security model built from bounded authority, measured execution, and evidence that survives every hop.</p>
]]></content:encoded></item><item><title>Confidential Computing</title><link>https://pawankhandavilli.com/topics/confidential-computing/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://pawankhandavilli.com/topics/confidential-computing/</guid><description>How trusted execution environments protect data in use—and what it takes to make their assurances verifiable.</description><content:encoded><![CDATA[<p>Confidential computing protects data while it is being processed. The interesting question is not whether a workload runs inside a trusted execution environment, but whether the complete path from measurement to attestation to secret release deserves trust.</p>
<h2 id="start-here">Start here</h2>
<ol>
<li><a href="/posts/whatsapps-private-processing-confidential-computing-at-internet-scale/">WhatsApp&rsquo;s Private Processing</a> introduces confidential computing through a system operating at internet scale.</li>
<li><a href="/posts/what-whatsapps-trail-of-bits-audit-teaches-us-about-real-tee-security/">What WhatsApp&rsquo;s Trail of Bits Audit Teaches Us</a> shows how real implementations can break the intended trust model.</li>
<li><a href="/posts/from-trust-us-to-verify-us-anthropic-confidential-inference/">From “Trust Us” to “Verify Us”</a> explores confidential AI inference and the next identity problem.</li>
<li><a href="/posts/tees-in-crypto-the-useful-middle-ground-between-pure-trust-and-pure-math/">TEEs in Crypto</a> looks at hardware isolation as a pragmatic coordination layer.</li>
<li><a href="/posts/follow-the-data/">Follow the Data</a> offers the broader architecture method behind the technology.</li>
</ol>
<p>These pieces move from the basic promise—protecting data in use—to the harder work of proving what is actually inside the trusted boundary.</p>
]]></content:encoded></item><item><title>Security Product Leadership</title><link>https://pawankhandavilli.com/topics/security-product-leadership/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://pawankhandavilli.com/topics/security-product-leadership/</guid><description>Practical lessons about security architecture, product judgment, and making trust an enabler rather than a gate.</description><content:encoded><![CDATA[<p>Security becomes more useful when it shapes product decisions early. These essays connect architecture, customer value, and the judgment required to ship systems people can trust.</p>
<h2 id="start-here">Start here</h2>
<ol>
<li><a href="/posts/follow-the-data/">Follow the Data</a> presents the five questions I use to make unfamiliar security architecture problems clearer.</li>
<li><a href="/posts/making-security-an-enabler/">Making Security an Enabler</a> explains how security teams can replace late-stage vetoes with early design partnership.</li>
<li><a href="/posts/from-nfc-startups-to-confidential-computing-my-journey-through-the-world-of-trusted-service-providers/">From NFC Startups to Confidential Computing</a> traces the career experiences behind that perspective.</li>
<li><a href="/posts/the-ai-security-stack-what-enterprises-need-to-secure-from-weights-to-workflows/">The AI Security Stack</a> turns the ideas into an executive operating model.</li>
</ol>
<p>The common theme is simple: start with the asset and the user outcome, make the trust boundary explicit, and design controls that help the product move.</p>
]]></content:encoded></item></channel></rss>