Security engineering research
Empirical investigations into default configurations, AI serving stacks, and cloud isolation boundaries.
Sorami conducts repeatable, empirical security research to measure what software actually ships with versus what operators assume. All findings are verified on local clusters or isolated test environments with zero vendor tracking or paywalls.
Full reproducible findings.
The Hidden Network: Ray Control-Plane Exposure
What a pod in an unrelated namespace could reach on default Ray and vLLM deployments in one Amazon EKS testbed, and what NetworkPolicy blocked.
29 September 2026
Read technical reportPolicy-Enforced Egress in AI Agent Sandboxes: NVIDIA OpenShell v0.1.2
Sorami Technical Report. The default policy blocked every exfiltration path tried; read-write rules, query or header values on read-only rules, audit mode and automatic approval let data out. Every result links to its log.
29 September 2026
Read technical reportAI on Kubernetes Helm Security Report
Security defaults and attack paths across 15 AI serving, vector database and MCP Helm charts, tested live on kind.
24 September 2026
Read technical reportThe data behind each report is public on GitHub: the Hidden Network report data and logs and the Helm chart results.
Move from findings to production assurance.
- AI production readiness review for LLM architectures and tooling.
- Cloud penetration testing for container and IAM privilege escalation paths.
- Cloud security review for configuration baselines across AWS, Azure, and GCP.
Next step
Running AI agents with tool, shell or network access? AI agent security review maps what each agent can reach and change on your own stack, the same boundaries these reports test. Contact us to discuss scope.
Have an AI workload deploying to Kubernetes?
Send your architecture and target release date. We will provide a fixed-scope review of access boundaries, secrets, and injection vectors before you launch.
Last reviewed: