RESEARCH & RESOURCES

Build a decision on evidence.

Original analysis, practical evaluation guidance, and clear explanations of the AI traffic boundary.

START HERE

INCIDENT REPLAY · MILGRAM

OpenAI-Hugging Face:
the warning signs.

34 signals across 16 reconstructed trajectories. Explore the timeline, what the engine detected, and the limits of the potential advance-warning claim.

Read the replay

BUYER GUIDE · MILGRAM

How to evaluate
an LLM firewall.

A practical plan for validating coverage, false positives, enforcement timing, data handling, and inference cost on your own workflows.

Use the evaluation guide

UNDERSTAND THE CATEGORY

Questions behind
the buying decision.

Direct answers to the architectural questions that determine whether a control fits your environment.

What is an LLM firewall?

An LLM firewall inspects AI traffic and applies controls around the context exchanged with model providers. Milgram adds session reconstruction, threat detection, policy enforcement, and deterministic compression at that boundary. Its coverage depends on the traffic routed through it.

How is this different from a provider’s safety filter?

A provider’s safety behavior operates within that provider’s model and service. An enterprise traffic layer can provide organization-specific policies and session evidence across supported provider integrations. Both remain part of a broader control system.

Why does session context matter?

A single tool result or request may be benign on its own. Session context connects it to the assigned task, earlier signals, and later actions. That can reveal escalation or drift that is difficult to assess message by message.

Can AI help maintain deterministic rules?

Yes, through a permissioned interface such as Milgram’s MCP connection. A customer-controlled AI can investigate evidence, draft or adapt rules, and correct false positives. Those changes still need validation and a controlled rollout.

FROM THE RESEARCH BLOG

Go deeper on the risks and tradeoffs.

PROMPT INJECTION

When external content becomes an instruction.

Explore prompt injection and the boundary between untrusted data and agent behavior.

Read the research

PROVIDER CONTROLS

What provider safety filters leave to the enterprise.

Understand why model-level safety and organization-specific controls answer different questions.

Read the research

SENSITIVE DATA

What your AI prompts send out.

Examine the data visibility gap created as employees and applications adopt AI tools.

Read the research

INFERENCE COST

The cost of growing context.

Look at how accumulated history affects the requests that long-running AI workflows send.

Read the research

INVITE-ONLY BETA

Bring your workflow. Define your evaluation.

Tell us what you use, what you need to protect, and where Milgram would run.

Talk to Milgram