Research
Decryption baiting
An encrypted archive was survivable for thirty years because opening it required a person. We named one after its own password and asked five agents to summarise the folder. All five opened it, none asked first, and one derived the password from the filename before it had evidence the file was even encrypted.
Sep 20, 2026
Research
Approved use is the risk
The agents you blocked were never going to hurt you much. The one you approved is wired into everything and nobody is watching what it reads or what it sends. Every employee works behind a mail filter, a proxy and DLP. The agent got the permissions and nothing else.
Sep 7, 2026
Product update
The agent reads it first
A tool call puts file content inside the model before anyone sees a screen. The controls at that boundary check the call, not what comes back. Subtext for MCP inspects the content, and the same engine runs at the gateway for what the client fetches itself.
Aug 17, 2026
Research
Prompt injection is not one thing
Three different attacks travelled in a single calendar invite and hit five agent products. Only one of them has no marker to detect. Why the file half of this is not being solved by sanitization, and why we redacted every payload in the article.
Aug 16, 2026
Research
If it has to phone home to decide, the internet is part of your file security
If deciding requires uploading the file, the decision already moved the file off your boundary. For an egress control that is the exact thing you were trying to prevent, performed by the thing you bought to prevent it.
Jul 28, 2026
Research
A control you cannot explain is a control you cannot defend
The signals are statistical. Of course they are. Determinism means three other things: no drift, no per-user state, and a reason you can read. An unexplainable control does not survive contact with an organization.
Jul 24, 2026
Research
You do not need to know a file exists to stop it crossing
The dominant model says find everything first, then protect what you found. The map is never finished, and everything not on it is unprotected by definition. A boundary does not need a map.
Jul 23, 2026
Research
An agent protects the machines you remembered
Bind a control to the device and its coverage is a roster. Rosters are always wrong, and they are wrong in the direction that hurts. Why file enforcement binds to the path, not the endpoint.
Jul 22, 2026
Research
The same file is not the same decision
A design document between two teams is routine. The same document to a personal drive is an incident. Nothing about the file changed. Why a verdict is a function of content and position, not identity.
Jul 21, 2026
Research
A file does not know which direction it is going
Security split one problem into two markets. Inbound got twenty-five years of investment; outbound got regular expressions. The same concealment your sandbox catches on the way in walks out unchallenged.
Jul 20, 2026
Research
A file’s type is a claim, and your stack treats it as a fact
The extension, the MIME type, and the magic bytes are all assertions from an untrusted party. Zero Trust re-verifies every claim a user, device, or network makes, then takes a file’s word for what it is. Content over declaration is where Zero Trust for Files starts.
Jul 16, 2026
Research
ClickFix hands the user the payload and asks them to run it
The malware never downloads. A fake verification page tells the reader to paste a command and press Enter, and the stack sees a harmless HTML file. Why ClickFix is a content problem, and what reads it.
Jul 13, 2026
Product update
Subtext now reads audio and video, not just documents
Secrets don’t only travel as text. A password read aloud in a voice memo, or a credential block painted into a spectrogram, is exfil too, so Subtext listens and looks, then reads the result.
Jul 9, 2026
Research
Every file is text now, and that changes what a boundary has to check
AI ingestion collapsed formats, passwords, and encodings into one thing: text a model will read. The old idea of a “protected” file is gone. Here’s why inspection has to meet the file on that plane.
Jun 24, 2026