Every AI Attack Is
A Remote Attack First.
Attacks Run At Machine Speed
Reconnaissance and exploitation are automated now. A model endpoint that holds a public address is not found in months, it is found in minutes, by something that never gets tired and never moves on. Whatever you were relying on being obscure is not obscure.
The Model Is The Way In
Prompt injection, jailbreaks, adversarial inputs, model extraction, denial of wallet. Every one of them has to reach your endpoint before it can be any of those things. They are remote attacks wearing a new name, and they fail at the network before they get to be clever.
The Answer Is The Exfiltration
An attacker who can query your model can ask it about the documents it was shown. And the index behind it holds those documents in a second, readable form, reachable on its own. Closing the model and leaving the index open just moves the door.
- Endpoints found by automated scanning in minutes
- Prompt injection carried inside a document it ingests
- A leaked key that works from anywhere on earth
- The index queried directly, going around the model
- Answers used to walk out with what it was shown
- No public address on the model endpoint
- No public address on the index behind it
- No public address on the document store
- Keys stop working: identity only, and revocable
- Only your own address ranges reach any of it
See What An Attacker Can Reach
Nerve AI Blocker runs on your machine, not ours. In a demo we point it at your own Azure, AWS, or Google Cloud account and it finds the AI services already running in it — live, read-only, nothing uploaded.
You see what your AI services expose. Every model endpoint and search index a stranger can reach, the rule that makes it reachable, and whether a key is the only thing standing in the way.
You see where the documents sit. Securing the model and leaving the index open protects nothing, because the index holds the same material in a second, readable form. All three parts are shown together.
Then you see it closed. Not new engineering. The private endpoints and network rules the rest of your stack already uses, pointed at the resource that escaped them.
$ nerve-backend connect aws ✓ Using local profile (no credentials sent) ✓ Read-only access verified $ nerve-backend plan Network isolation ....... 14 resources Private endpoints ....... 9 resources Access restrictions ..... 7 resources Nothing applied. Review above. $ nerve-backend apply ✓ Deployed to your account ✓ Templates written to ./nerve-backend/
Nothing is installed on your side to see this, and nothing is deployed into your account without you agreeing to the full list first. If you stop after the findings, you keep the findings.
Three Doors, Closed Together
Three parts, and they hold the same material. Any product that closes one and leaves the other two is selling a feeling rather than a posture.
The model endpoint
Where the prompts go
Azure OpenAI, Cognitive Services, Bedrock or Vertex. Usually public behind a single key, and usually stood up outside whatever review the rest of the estate went through.
The search index
What the AI has been shown
A vector or search index holding your documents in a second, readable form. Securing the model and leaving this reachable protects nothing.
The document store
What it was built from
The originals. They outlive any one model, they are usually the least guarded thing in the estate, and they are what an attacker is actually after.
Deploys today on Microsoft Azure. Amazon Web Services and Google Cloud are read today and are an emitter away from deploying, because the blueprint itself contains no provider names.
Take Away What They Have To Reach
This is not a prompt filter. It does not read your prompts, score them, or sit in the path of an answer. Anything that does is one more thing to bypass, and it has to be reachable to work at all.
It removes the surface instead. A model endpoint with no public address cannot be scanned, cannot be queried by a stolen key from an unknown network, and cannot be reached by an automated attack no matter how clever the payload is. The attack fails at the network, before it gets to be an AI problem.
The pen-tested architecture already contained this: the original federal template puts a Cognitive Services account behind a private endpoint. Nothing here is new engineering, which is exactly the reason to trust it — it is the posture the rest of your stack already runs on, pointed at the one resource that escaped it.
Nothing To Scan
An automated sweep looking for exposed model endpoints does not find yours, because there is no public address on it to find. The cheapest attack in the catalogue stops working first.
A Stolen Key Is Not Enough
Local authentication is disabled, so a key pasted into a notebook, a config file or a chat message opens nothing from outside your network. The credential stops being the whole perimeter.
Injection Still Has To Arrive
A malicious instruction hidden in a document is only an attack if something can deliver it to your model. Closing the endpoint does not make prompts safe, it makes them reachable only from inside your own network.
The Index Cannot Be Read Directly
A vector index holds your documents in a second, readable form and answers queries of its own. Closed in the same step as the model, so going around it is not an option either.
Exfiltration Has Nowhere To Go
The document store behind the index is closed too. What the model was shown outlives any one model, and it is what an attacker is actually after.
Found, Not Declared
It reads the account rather than asking you what you have. A business unit that stood up a model endpoint last month is not going to file a ticket about it, and an attacker will not wait for one.
Connect With Us
Headquarters
NERVE PLUS Inc
101 Jefferson Street, Floor 1
Menlo Park, CA 94205
Federal Division
1801 K Street NW
Washington, DC 20006
Contact
Enterprise Solutions
enterprise@nerveplusinc.com
+1 (650) 665-6100