Post #3997927
2026-07-17 21:22 UTC
@DavidJBianco@infosec.exchange open source LLM should be what companies use for incident response, giving the ai companies access to sensitive data from an incident can’t be good in the first place
Replies (1)
-
@DavidJBianco@infosec.exchange 2026-07-17 21:48
@csec@infosec.exchange As I mentioned in another reply, that part is really risk management. There are multiple strategies, including using only local models or setting contractual limits on how the cloud provider treats your data. Local models probably provide the highest level of assurance, but push the cost (both monetary and non-monetary) onto the org. In some cases, using a cloud provider might actually be the "best" choice, but it's highly dependent on circumstances.