Application Security
Research on authentication, authorization, tenant isolation, API trust boundaries, runtime protection, and agent/tool security.
- API and microservice trust boundaries
- OAuth 2.0 and OpenID Connect
- SaaS multi-tenancy isolation
- Runtime protection with RASP, WAF, and eBPF
- Threat-driven security architecture for AI agents