Insights
Notes from the
build.
Practical, opinionated writing on shipping secure AI chat and voice agents in regulated industries — HIPAA architectures, LLM guardrails, voice-agent latency, and the things we learn in the wild.
Reference architecture
16 Sep 2026 · 12 min read
What it actually takes to run a patient-facing voice agent that survives a security review — from BAA-covered LLMs and STT/TTS providers, through PHI-aware guardrails, to audit trails that satisfy HHS §164.312.
Read the piece ↗
Coming soon
Draft · in review
Red-teaming an LLM agent before production
A concrete playbook mapped to the OWASP Top 10 for LLM Applications: prompt-injection payloads, tool-abuse tests, data-exfiltration probes, and how to score what you find.
Publishing shortly ·
Coming soon
Draft · in review
DPDP Act 2023: what actually changes for AI agents
A practical read of India's new data-protection law for teams building conversational AI — consent, purpose limitation, cross-border transfer, and the Data Principal-rights workflows you'll need to bolt onto your agent.
Publishing shortly ·
Coming soon
Draft · in review
Voice-agent latency budget: hitting 800ms end-to-end
Where the milliseconds actually go — STT, first-token, TTS chunking, network — and how to design an agent architecture that stays under one perceivable second on Bedrock or Azure.
Publishing shortly ·