<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on Alex Herrero</title><link>https://alexherrero.dev/tags/security/</link><description>Recent content in Security on Alex Herrero</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Tue, 09 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://alexherrero.dev/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>A security gate you can poke</title><link>https://alexherrero.dev/thoughts/crickets-intercept-gate/</link><pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate><guid>https://alexherrero.dev/thoughts/crickets-intercept-gate/</guid><description>An interactive, deterministic intercept-gate — propose a command and watch a no-LLM ruleset allow, hold, or block it, with its reason.</description></item><item><title>A security person's case for boring, auditable AI tooling</title><link>https://alexherrero.dev/thoughts/boring-auditable-ai-tooling/</link><pubDate>Fri, 05 Jun 2026 00:00:00 +0000</pubDate><guid>https://alexherrero.dev/thoughts/boring-auditable-ai-tooling/</guid><description>Useful-enough-to-depend-on and safe turn out to be the same problem. The boring path &amp;ndash; deterministic gates, legible state &amp;ndash; is the one that scales trust.</description></item></channel></rss>