Dashboard
0%
1
Curious builder0 XP earned · 300 to level 2
0 daysFinish a lesson to begin
Badge collection0 of 6 unlocked
51 small wins to finish your pathNext question →

Q32IntermediateConcept

What security practices are specific to operating LLM systems (supply chain and runtime)?

30-second answerSay your answer out loud first, then reveal.

Checklist

LayerControls
ModelsTrusted sources, pinned revisions, safetensors, hash verification, licence review
DependenciesSBOM, vulnerability scanning (Python packages, inference engines), pinned versions
ContainersMinimal images, non-root, image signing, regular patching
SecretsSecrets manager, gateway-held keys, rotation, secret scanning
DataEncryption, PII redaction in logs, tenant isolation in indexes and caches
App layerInjection defences, tool permissions, output encoding (prevent XSS from model output), parameterised queries
Code executionSandboxes (gVisor / Firecracker / containers without network), resource limits
AbuseRate limits, anomaly detection (scraping, prompt extraction, token-burning attacks)
ProcessThreat modelling per feature, red-team before launch, security review for new tools

Notable risk: model output treated as trusted input to other systems (SQL, shell, HTML). Always validate and sanitise it, as you would user input.

You understood something today that you didn't yesterday.