Blog
Practical guides to Google Workspace security, data security posture management, OAuth audits, compliance, and risk — from the 8200.dev team.
- 7 min read
What the OpenAI–Hugging Face Incident Actually Means for Enterprises
OpenAI models escaped an isolated test sandbox and reached Hugging Face production systems. What happened, what did not, and what it means for your AI agents.
AIGovernanceSecurityAI AgentsRead article → - 8 min read
See Every AI Tool Touching Your Org — Sanctioned or Shadow
Introducing AI Governance in 8200.dev: one dashboard for shadow AI discovery, agentic platforms like Manus, vendor training posture, and AI-vendor key hygiene.
AI GovernanceShadow AIManusProductRead article → - 8 min read
Security Obligations That Already Apply to You as an Independent Developer
Freelancers and indie developers carry real GDPR, EU AI Act, and contractual security obligations — here is what already applies, and what to check first.
FreelancersGDPREU AI ActGitHub SecurityComplianceRead article → - 8 min read
The AI Opt-Out That Doesn’t Exist: What We Found Checking 17 SaaS Platforms
We checked all 17 platforms in 8200.dev’s connector library to see who trains AI on your content by default — and where each opt-out actually lives.
AI GovernanceData ContributionSaaS SecurityComplianceRead article → - 7 min read
Is Atlassian Training AI on Your Jira Data? Here’s What Changes on August 17
What Atlassian’s new data-contribution settings mean for Jira, Confluence, and JSM admins — and what to check before August 17, 2026.
AI GovernanceAtlassianJiraData ContributionRead article → - 7 min read
You Built It With Lovable — Who's Responsible When It Leaks Data?
Building an app with Lovable or Base44 is fast — but the company that deploys it is the data controller. What that means for AI-built app security and liability.
AIGovernanceShadow ITComplianceRead article → - 6 min read
Who Is Liable When Your AI Agent Leaks Data? The 2026 Legal Reality
Courts increasingly hold the company deploying AI — not just the vendor — accountable for what its agents do. A clear, factual look at the 2026 liability landscape.
AILiabilityGovernanceComplianceRead article → - 6 min read
AI Governance Compliance: What Auditors Now Require in 2026
AI governance is now a standard audit line item. A practical guide to what auditors expect in 2026 — and how to have the evidence ready before they ask.
ComplianceAIAuditGovernanceRead article → - 7 min read
Google Workspace Security: The Complete Guide for IT Admins (2026)
A practical, end-to-end guide to securing Google Workspace: identity, Drive sharing, OAuth apps, admin settings, and the monitoring that keeps it all in check.
Google WorkspaceSecurityIT AdminGuideRead article → - 7 min read
How to Audit Third-Party OAuth Apps in Google Workspace
A step-by-step method for finding, assessing, and cleaning up the OAuth applications connected to your Google Workspace — the shadow IT hiding in plain sight.
Google WorkspaceOAuthShadow ITSecurityRead article → - 6 min read
What is DSPM? Data Security Posture Management Explained
A clear, jargon-free explanation of Data Security Posture Management (DSPM): what it is, how it differs from CSPM and DLP, and when an organization needs it.
DSPMData SecurityConceptsRead article → - 6 min read
Google Drive Sharing Permissions: A Security Checklist
A practical, repeatable checklist for reviewing Google Drive sharing permissions and closing the exposures that accumulate over time.
Google WorkspaceGoogle DriveSharingChecklistRead article → - 6 min read
SOC 2 Compliance for Google Workspace: What You Need to Know
How Google Workspace fits into a SOC 2 program: which Trust Services Criteria apply, what evidence auditors expect, and how to prepare without the scramble.
SOC 2ComplianceGoogle WorkspaceRead article → - 6 min read
How to Detect Risky AI Agents in Your Google Workspace
AI assistants and service accounts now hold standing access to Workspace data and act on it autonomously. Here is how to find and govern the risky ones.
Google WorkspaceAI AgentsSecurityIdentityRead article → - 6 min read
External File Sharing Risks in Google Workspace: How to Monitor and Control
External sharing is essential and risky in equal measure. Here is how to monitor it, control it, and keep collaboration from becoming exposure.
Google WorkspaceExternal SharingSecurityRead article → - 5 min read
Google Workspace vs Microsoft 365 Security: A Comparison
An even-handed comparison of the security models behind Google Workspace and Microsoft 365 — identity, sharing, third-party apps, and the gaps both leave.
Google WorkspaceMicrosoft 365ComparisonSecurityRead article → - 5 min read
How to Enforce MFA Across Your Google Workspace Organization
A practical rollout plan for enforcing 2-Step Verification across Google Workspace — including factor choices, exceptions, and avoiding lockouts.
Google WorkspaceMFAIdentityHow-toRead article → - 5 min read
The CISO's Guide to Google Workspace Risk Assessment
A structured approach for security leaders to assess Google Workspace risk: scope, methodology, the domains to evaluate, and how to report and track it.
Google WorkspaceRisk AssessmentCISOLeadershipRead article →