Nerve
AI Blocker

Hardened against AI attacks // No public endpoint to reach // Model, index and documents closed

ZERO Reachable AI Surface
THREE Parts Closed Together
ONE Proven Posture

Every AI Attack Is
A Remote Attack First.

01

Attacks Run At Machine Speed

Reconnaissance and exploitation are automated now. A model endpoint that holds a public address is not found in months, it is found in minutes, by something that never gets tired and never moves on. Whatever you were relying on being obscure is not obscure.

02

The Model Is The Way In

Prompt injection, jailbreaks, adversarial inputs, model extraction, denial of wallet. Every one of them has to reach your endpoint before it can be any of those things. They are remote attacks wearing a new name, and they fail at the network before they get to be clever.

03

The Answer Is The Exfiltration

An attacker who can query your model can ask it about the documents it was shown. And the index behind it holds those documents in a second, readable form, reachable on its own. Closing the model and leaving the index open just moves the door.

How AI Gets Attacked
  • Endpoints found by automated scanning in minutes
  • Prompt injection carried inside a document it ingests
  • A leaked key that works from anywhere on earth
  • The index queried directly, going around the model
  • Answers used to walk out with what it was shown
What Is Left To Attack
  • No public address on the model endpoint
  • No public address on the index behind it
  • No public address on the document store
  • Keys stop working: identity only, and revocable
  • Only your own address ranges reach any of it

See What An Attacker Can Reach

Nerve AI Blocker runs on your machine, not ours. In a demo we point it at your own Azure, AWS, or Google Cloud account and it finds the AI services already running in it — live, read-only, nothing uploaded.

You see what your AI services expose. Every model endpoint and search index a stranger can reach, the rule that makes it reachable, and whether a key is the only thing standing in the way.

You see where the documents sit. Securing the model and leaving the index open protects nothing, because the index holds the same material in a second, readable form. All three parts are shown together.

Then you see it closed. Not new engineering. The private endpoints and network rules the rest of your stack already uses, pointed at the resource that escaped them.

nerve-ai-blocker
$ nerve-backend connect aws
   Using local profile (no credentials sent)
   Read-only access verified

$ nerve-backend plan
  Network isolation ....... 14 resources
  Private endpoints ....... 9 resources
  Access restrictions ..... 7 resources
  Nothing applied. Review above.

$ nerve-backend apply
   Deployed to your account
   Templates written to ./nerve-backend/

Nothing is installed on your side to see this, and nothing is deployed into your account without you agreeing to the full list first. If you stop after the findings, you keep the findings.

Three Doors, Closed Together

Three parts, and they hold the same material. Any product that closes one and leaves the other two is selling a feeling rather than a posture.

01

The model endpoint

Where the prompts go

Azure OpenAI, Cognitive Services, Bedrock or Vertex. Usually public behind a single key, and usually stood up outside whatever review the rest of the estate went through.

Private endpoint Local auth disabled Public access denied
02

The search index

What the AI has been shown

A vector or search index holding your documents in a second, readable form. Securing the model and leaving this reachable protects nothing.

Private endpoint Public access denied Closed in the same step
03

The document store

What it was built from

The originals. They outlive any one model, they are usually the least guarded thing in the estate, and they are what an attacker is actually after.

Private endpoint Anonymous access off Shared keys disabled

Deploys today on Microsoft Azure. Amazon Web Services and Google Cloud are read today and are an emitter away from deploying, because the blueprint itself contains no provider names.

Take Away What They Have To Reach

This is not a prompt filter. It does not read your prompts, score them, or sit in the path of an answer. Anything that does is one more thing to bypass, and it has to be reachable to work at all.

It removes the surface instead. A model endpoint with no public address cannot be scanned, cannot be queried by a stolen key from an unknown network, and cannot be reached by an automated attack no matter how clever the payload is. The attack fails at the network, before it gets to be an AI problem.

The pen-tested architecture already contained this: the original federal template puts a Cognitive Services account behind a private endpoint. Nothing here is new engineering, which is exactly the reason to trust it — it is the posture the rest of your stack already runs on, pointed at the one resource that escaped it.

What You Receive
01Every AI service in the account, found and drawn
02The model endpoint closed behind a private endpoint
03The search index closed with it, in the same step
04The document store behind it closed too
05Local authentication disabled, so a leaked key opens nothing
01

Nothing To Scan

An automated sweep looking for exposed model endpoints does not find yours, because there is no public address on it to find. The cheapest attack in the catalogue stops working first.

02

A Stolen Key Is Not Enough

Local authentication is disabled, so a key pasted into a notebook, a config file or a chat message opens nothing from outside your network. The credential stops being the whole perimeter.

03

Injection Still Has To Arrive

A malicious instruction hidden in a document is only an attack if something can deliver it to your model. Closing the endpoint does not make prompts safe, it makes them reachable only from inside your own network.

04

The Index Cannot Be Read Directly

A vector index holds your documents in a second, readable form and answers queries of its own. Closed in the same step as the model, so going around it is not an option either.

05

Exfiltration Has Nowhere To Go

The document store behind the index is closed too. What the model was shown outlives any one model, and it is what an attacker is actually after.

06

Found, Not Declared

It reads the account rather than asking you what you have. A business unit that stood up a model endpoint last month is not going to file a ticket about it, and an attacker will not wait for one.

Connect With Us

Headquarters

NERVE PLUS Inc
101 Jefferson Street, Floor 1
Menlo Park, CA 94205

Federal Division

1801 K Street NW
Washington, DC 20006

Contact

Enterprise Solutions
enterprise@nerveplusinc.com
+1 (650) 665-6100