<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Overnight Blog</title>
    <link>https://tryovernight.com/blog/</link>
    <atom:link href="https://tryovernight.com/blog/rss.xml" rel="self" type="application/rss+xml" />
    <description>Field notes on running AI- and agent-generated software safely: compliance, audit, isolation, and the compliant runtime.</description>
    <language>en-us</language>
    <lastBuildDate>Tue, 21 Jul 2026 09:00:00 GMT</lastBuildDate>
    <item>
      <title>What Is a Compliant Runtime for AI-Generated Software?</title>
      <link>https://tryovernight.com/blog/what-is-a-compliant-runtime/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/what-is-a-compliant-runtime/</guid>
      <category>Fundamentals</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>A plain definition of a term you're going to hear a lot more of: an execution environment where AI- and agent-written code runs with isolation, a full audit trail, and policy enforcement applied by default. Safe on real data, and it passes security review without per-tool engineering.</description>
    </item>
    <item>
      <title>What Is an AI Agent Sandbox, and Where Sandboxes Stop</title>
      <link>https://tryovernight.com/blog/ai-agent-sandbox-explained/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/ai-agent-sandbox-explained/</guid>
      <category>Fundamentals</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>An AI agent sandbox is an isolated, disposable environment where an agent runs the code it just wrote. They are excellent at that job. The confusion starts when teams expect one to govern production software on real data, which is a different job entirely.</description>
    </item>
    <item>
      <title>AI Agents Are Writing Code That Touches Production Data. Who's Accountable?</title>
      <link>https://tryovernight.com/blog/ai-agents-production-data-accountability/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/ai-agents-production-data-accountability/</guid>
      <category>Governance &amp; Risk</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>Autonomous agents now write and run code against real customer data with no human in the loop. When that code causes a breach or a compliance failure, the org chart goes quiet. Here is where accountability actually has to land.</description>
    </item>
    <item>
      <title>The Audit Trail Problem: Proving What Ran and Who Approved It</title>
      <link>https://tryovernight.com/blog/ai-code-audit-trail/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/ai-code-audit-trail/</guid>
      <category>Compliance &amp; Audit</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>For AI-built software, the auditor's question (what ran against our data, and who approved it?) usually has no good answer. Here is why application logs can't provide one, and what a real record of autonomous execution actually requires.</description>
    </item>
    <item>
      <title>GDPR, HIPAA, and AI-Generated Software: The Data-Processing Blind Spot</title>
      <link>https://tryovernight.com/blog/ai-generated-code-gdpr-hipaa/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/ai-generated-code-gdpr-hipaa/</guid>
      <category>Compliance &amp; Audit</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>When AI-generated software processes personal data or PHI, the same rules apply as for any other processing. What changes is that the chain of accountability the regulations depend on quietly goes missing.</description>
    </item>
    <item>
      <title>A Security Checklist Before AI-Generated Code Touches Real Data</title>
      <link>https://tryovernight.com/blog/ai-generated-code-security-checklist/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/ai-generated-code-security-checklist/</guid>
      <category>Governance &amp; Risk</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>Seven checks a platform or security team can run before an AI-built app reads a single production record. Skimmable, reusable, and grounded in how the failures actually happen.</description>
    </item>
    <item>
      <title>How to Give an AI Model Capabilities Without Handing Over API Keys</title>
      <link>https://tryovernight.com/blog/ai-model-capabilities-without-api-keys/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/ai-model-capabilities-without-api-keys/</guid>
      <category>Security &amp; Architecture</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>The moment you give an agent a raw key so it can &quot;do things,&quot; the model and every line it writes holds the keys to the kingdom. There is a better shape, and it starts with handing over capabilities while the credentials stay put.</description>
    </item>
    <item>
      <title>Capability-Based Security for AI Agents, Explained</title>
      <link>https://tryovernight.com/blog/capability-based-security-ai-agents/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/capability-based-security-ai-agents/</guid>
      <category>Security &amp; Architecture</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>An agent should be able to do exactly what it was granted and nothing else. Capability-based security makes that true by construction, so you stop hoping a policy check fires in time.</description>
    </item>
    <item>
      <title>Code Provenance and Signing for AI-Generated Apps</title>
      <link>https://tryovernight.com/blog/code-provenance-signing/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/code-provenance-signing/</guid>
      <category>Security &amp; Architecture</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>The supply-chain toolkit already knows how to prove where an artifact came from and that nobody tampered with it. AI-generated apps break the assumption underneath it: that what you signed is what stays running.</description>
    </item>
    <item>
      <title>Deny-by-Default: Designing Guardrails AI-Generated Code Can't Escape</title>
      <link>https://tryovernight.com/blog/deny-by-default-guardrails/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/deny-by-default-guardrails/</guid>
      <category>Security &amp; Architecture</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>You can't predict what a model will write, so you can't enumerate everything it might do wrong. The only guardrail that holds denies everything you didn't explicitly allow, and enforces that where the code runs.</description>
    </item>
    <item>
      <title>Pass Security Review Once: Inheriting Compliance Posture Across Apps</title>
      <link>https://tryovernight.com/blog/inherit-compliance-posture/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/inherit-compliance-posture/</guid>
      <category>Compliance &amp; Audit</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>Every new app arrives at the review queue as a fresh unknown, with its own questionnaire, its own evidence, its own controls to re-prove. When AI generates apps faster than any queue can drain, that per-app tax becomes the bottleneck. There is an architectural way out.</description>
    </item>
    <item>
      <title>Is AI-Generated Code Safe? What the 2026 Data Actually Says</title>
      <link>https://tryovernight.com/blog/is-ai-generated-code-safe/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/is-ai-generated-code-safe/</guid>
      <category>Fundamentals</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>AI writes code that passes your tests and ships to production. The security data tells a very different story. Here is what the studies show, and why the durable fix lives in the place the code runs.</description>
    </item>
    <item>
      <title>Overnight vs. Cloudflare Workers &amp; Sandboxes: Edge Execution vs. a Governed Runtime</title>
      <link>https://tryovernight.com/blog/overnight-vs-cloudflare/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/overnight-vs-cloudflare/</guid>
      <category>Comparisons</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>Cloudflare runs code closer to your users than almost anyone, and now gives AI agents isolated sandboxes to execute in. Proving to an auditor that AI-built software touched real data safely is a different job. Here is an honest look at where each one fits.</description>
    </item>
    <item>
      <title>Overnight vs. Daytona: Sandbox Infrastructure vs. a Compliant Runtime</title>
      <link>https://tryovernight.com/blog/overnight-vs-daytona/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/overnight-vs-daytona/</guid>
      <category>Comparisons</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>Daytona is one of the fastest ways to give an AI agent an elastic, isolated place to run code. Running AI-built software safely on production data is a different job. Here is an honest breakdown of where each one fits.</description>
    </item>
    <item>
      <title>Overnight vs. E2B: Sandbox Execution vs. a Governed Runtime</title>
      <link>https://tryovernight.com/blog/overnight-vs-e2b/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/overnight-vs-e2b/</guid>
      <category>Comparisons</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>E2B is one of the best ways to give an AI agent a fast, isolated place to run code. Running AI-built software safely on production data is a different job. Here is an honest breakdown of where each one fits.</description>
    </item>
    <item>
      <title>Overnight vs. Modal: Serverless Compute vs. a Governed Runtime</title>
      <link>https://tryovernight.com/blog/overnight-vs-modal/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/overnight-vs-modal/</guid>
      <category>Comparisons</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>Modal is one of the strongest serverless compute platforms for AI and ML, and its sandboxes are a clean way to execute untrusted, model-generated code. Governing what AI-built software does with your production data is a different job. Here is an honest breakdown of where each one fits.</description>
    </item>
    <item>
      <title>Overnight vs. Vercel Sandbox: Ephemeral Execution vs. a Compliant Runtime</title>
      <link>https://tryovernight.com/blog/overnight-vs-vercel-sandbox/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/overnight-vs-vercel-sandbox/</guid>
      <category>Comparisons</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>Vercel Sandbox is a clean, fast way to run untrusted or generated code inside the Vercel platform. Running AI-built software safely on production data is a different job. Here is an honest breakdown of where each one fits.</description>
    </item>
    <item>
      <title>How to Run AI-Generated Code Safely in Production</title>
      <link>https://tryovernight.com/blog/run-ai-generated-code-safely/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/run-ai-generated-code-safely/</guid>
      <category>Fundamentals</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>A model can write and ship an app before anyone reads it. Here is the practical playbook for letting that code touch real data without trusting a line of it.</description>
    </item>
    <item>
      <title>Sandbox vs. Compliant Runtime: The Difference That Matters in Production</title>
      <link>https://tryovernight.com/blog/sandbox-vs-compliant-runtime/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/sandbox-vs-compliant-runtime/</guid>
      <category>Fundamentals</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>From a distance a sandbox and a compliant runtime look like the same box: somewhere safe to put untrusted code. They answer different questions, and only one of them survives an audit. Here is the clean line between them.</description>
    </item>
    <item>
      <title>Shadow AI: How Ungoverned AI Apps Become Your Next Compliance Incident</title>
      <link>https://tryovernight.com/blog/shadow-ai-ungoverned-apps/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/shadow-ai-ungoverned-apps/</guid>
      <category>Governance &amp; Risk</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>The old worry was employees pasting secrets into a chatbot. The new one is agents that build and run whole apps against your production data, with no owner, no review, and no record of what happened.</description>
    </item>
    <item>
      <title>Ship AI-Built Internal Tools Without a Procurement Cycle</title>
      <link>https://tryovernight.com/blog/ship-ai-internal-tools-without-procurement/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/ship-ai-internal-tools-without-procurement/</guid>
      <category>Governance &amp; Risk</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>You can build the internal tool your team needs in an afternoon. Shipping it the sanctioned way can take a quarter. Here is how to get both: first-session value inside a boundary security already signed off on.</description>
    </item>
    <item>
      <title>SOC 2 and AI-Generated Code: What Auditors Now Expect</title>
      <link>https://tryovernight.com/blog/soc-2-ai-generated-code/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/soc-2-ai-generated-code/</guid>
      <category>Compliance &amp; Audit</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>The controls didn't change. What generates the code did. Here is how SOC 2's change management, access, and monitoring criteria read once an agent wrote and shipped the app with no human in the loop.</description>
    </item>
    <item>
      <title>Subprocessor of Record: Why Runtime Responsibility Decides Enterprise Deals</title>
      <link>https://tryovernight.com/blog/subprocessor-of-record/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/subprocessor-of-record/</guid>
      <category>Compliance &amp; Audit</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>Every enterprise deal that touches customer data runs into the same gate: can we list you as a subprocessor? For AI-built software the honest answer is usually that nobody qualifies, and that empty line on the list is where launches die.</description>
    </item>
    <item>
      <title>Tenant Isolation for AI Apps: Shared Pool vs. Per-Tenant Boundary</title>
      <link>https://tryovernight.com/blog/tenant-isolation-for-ai-apps/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/tenant-isolation-for-ai-apps/</guid>
      <category>Security &amp; Architecture</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>Pooled infrastructure is cheaper, and for most workloads it is fine. AI-generated code running on real customer data sits outside most workloads. Here is how the isolation spectrum works, and why the choice turns into a security decision.</description>
    </item>
    <item>
      <title>Vibe Coding in the Enterprise: The Security Gap Nobody Owns</title>
      <link>https://tryovernight.com/blog/vibe-coding-enterprise-security/</link>
      <guid isPermaLink="true">https://tryovernight.com/blog/vibe-coding-enterprise-security/</guid>
      <category>Governance &amp; Risk</category>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <description>Vibe coding is genuinely productive, and it has quietly moved from weekend projects into real internal tools. The practice is fine. What goes wrong is that nobody owns what happens after the code ships.</description>
    </item>
  </channel>
</rss>
