Behind the Glass — field notes from a live deployment

It Is Not Only Customers Who Call at Night

October 5, 2026 · Security of agent systems

In this journal we mostly write about how the agent learns to speak. There is a second half of the work that does not make it into product decks: all of this machinery is being tested for weaknesses around the clock.

2026 produced a new class of target. Once you attach tools to a language model — mail, a browser, a command line, a database — it stops being an interlocutor and becomes an executor. The protocol used to attach them went mainstream within a year, and the scanners that look for such connections on the open internet arrived with it. Trend Micro counted hundreds of exposed servers and a threefold rise over nine months. Wiz ran a honeypot for ninety days and described what the finders do: install a miner that lives in memory and never writes a file to disk, pull API keys straight out of process memory, hide binaries in folders with innocent names. OWASP, in its June report, puts it plainly: injected instructions remain the leading cause of security failures in agentic systems in production.

The ugly part of this class is that the attack goes after the agent, not the server. The agent honestly reads an email, a web page or an error message, and inside sits an instruction addressed not to a human but to it. The tools are clean. The data is poisoned.

We do not know this from articles. We run our own servers, our own infrastructure and our own agents, all of it visible from the internet, which means it is tested by other people’s hands every night. We keep a record of those attempts, we take each one apart, and after each one we change how the system is built — not just a password. The rules we have arrived at sound simple and are inconvenient to work with: an agent that reads text from the outside world is not allowed to execute commands; nothing faces the internet without real access control, and a secret address does not count as protection; no foreign code runs without being read first; updates do not arrive on their own.

Why we are telling you this. Because the promise that your data never leaves for someone else’s cloud is worth exactly as much as the defence of the machine where it stays. Owning your infrastructure is not only independence, it is also an obligation. The work is not easy, and we are not pretending otherwise.

The specifics of our own defences, for obvious reasons, are not printed here.