AI Security & Compliance
DPDP, tenant isolation, audit evidence and cluster security.
9 articlesIncident Response for AI Clusters: Containment, Forensics and Notification Duties
GPU-cluster incidents look different: cryptojacking, stolen pipeline credentials, model exfiltration - and containment decisions collide with week-long training runs. How to contain without destroying work in progress, what forensics on…
Network and Access Security for GPU Clusters: Segmentation, Jump Hosts and Secrets
A GPU cluster concentrates an organisation's most valuable data, most expensive compute and most privileged credentials in one place. A reference security architecture: network zones, RDMA fabric exposure, jump-host access…
Sector Rules Beyond DPDP: RBI, Health Data and Government Procurement
DPDP is the general law, but the binding constraints on AI infrastructure often come from sector instruments: RBI's payment data direction and FREE-AI framework, ABDM and EHR standards in health,…
Supply Chain and Firmware Integrity for GPU Servers: Secure Boot to Counterfeits
A GPU server's trustworthiness is decided before the OS boots. How to verify hardware provenance and avoid grey-market and counterfeit GPUs, what secure boot and signed firmware actually attest, why…
Model and Data Governance On-Prem: Registries, Lineage and Approval Gates
Governance is what separates a compliant private AI platform from a fast one that fails review. How a model registry, dataset lineage and approval gates work on owned GPU infrastructure,…
Audit Evidence for AI Systems: What Auditors Ask For and How to Build It In
AI audits fail on evidence, not intent. What an auditor actually requests from an AI system - access records, change history, dataset lineage, model documentation, retention proof - and how…
Data Residency Architectures for AI: Where Personal Data May and May Not Flow
DPDP permits cross-border transfer except to restricted countries, so real residency duties come from sector overlays - RBI payment data, government workloads, contracts. Three reference architectures for keeping personal data…
Tenant Isolation on Shared GPUs: MIG, vGPU and Time-Slicing Compared
MIG partitions memory, cache and compute in hardware; vGPU adds hypervisor mediation; time-slicing and MPS share one memory space and are not security boundaries. What each mechanism does and does…
The DPDP Act for AI Infrastructure: What It Requires and What It Does Not
The DPDP Act 2023 and the Rules notified in November 2025 govern how personal data in AI systems is secured, reported and erased - but they do not mandate blanket…