# Thiago Silva | Cyber Architect > Thiago Silva — Cyber Architect. AWS and GCP security architecture, DevSecOps, leadership, FinOps and digital transformation. Content produced with AI assistance for Thiago Silva’s website. Independent editorial analysis; it does not represent clients or employers. Collection published on September 12, 2026. Months organize the reading path; they are not earlier publication dates. ## Profile - [Profile](https://thiago.limaesilvatecnologia.com.br/en/perfil/index.md): https://thiago.limaesilvatecnologia.com.br/en/perfil/ - [LinkedIn](https://www.linkedin.com/in/tlimasilva) ## Articles - [Articles](https://thiago.limaesilvatecnologia.com.br/en/artigos/) - [RSS](https://thiago.limaesilvatecnologia.com.br/en/feed.xml) - [Cloud SQL: database location does not finish the security review](https://thiago.limaesilvatecnologia.com.br/en/artigos/cloud-sql-regional-control-plane/index.md): Regional administrative API endpoints raise an architecture question: where do the operations that manage your data travel? - [Access control: who decides and who executes?](https://thiago.limaesilvatecnologia.com.br/en/artigos/access-control/index.md): Clear responsibilities prevent ownerless permissions. - [Attack surface: include the forgotten paths](https://thiago.limaesilvatecnologia.com.br/en/artigos/attack-surface/index.md): Reviewing only the main application misses integrations. - [Authentication: design beyond login](https://thiago.limaesilvatecnologia.com.br/en/artigos/authentication-journeys/index.md): Device changes and recovery also establish trust. - [Authorization: turn business rules into testable decisions](https://thiago.limaesilvatecnologia.com.br/en/artigos/authorization-decisions/index.md): A user role alone does not explain resource access. - [CI/CD: every stage carries a trust boundary](https://thiago.limaesilvatecnologia.com.br/en/artigos/pipeline-trust/index.md): Building code and authorizing production are different decisions. - [CSP: treat adoption as a dependency migration](https://thiago.limaesilvatecnologia.com.br/en/artigos/csp-migration/index.md): A sustainable policy needs script owners. - [CSRF: review state-changing operations](https://thiago.limaesilvatecnologia.com.br/en/artigos/csrf-business-flows/index.md): Risk depends on how the browser sends session authority. - [Additional encryption: which threat does it address?](https://thiago.limaesilvatecnologia.com.br/en/artigos/envelope-data-boundary/index.md): Application encryption changes exposure boundaries and operations. - [Database roles: separate queries, maintenance and recovery](https://thiago.limaesilvatecnologia.com.br/en/artigos/database-roles/index.md): A shared credential hides distinct operational decisions. - [Availability: budget expensive operations](https://thiago.limaesilvatecnologia.com.br/en/artigos/availability-budgets/index.md): Request counts can hide large differences in work. - [SBOM: from component list to response decision](https://thiago.limaesilvatecnologia.com.br/en/artigos/sbom-operational/index.md): Inventory must connect to running software. - [Containers: follow the review into runtime](https://thiago.limaesilvatecnologia.com.br/en/artigos/container-runtime/index.md): An approved image still depends on deployment permissions. - [API errors: a contract for clients and operations](https://thiago.limaesilvatecnologia.com.br/en/artigos/error-contracts/index.md): Public responses and internal diagnostics serve different audiences. - [Uploads: receiving a file does not release it](https://thiago.limaesilvatecnologia.com.br/en/artigos/upload-quarantine/index.md): Model states between ingestion, inspection and use. - [Account recovery: support is part of the control](https://thiago.limaesilvatecnologia.com.br/en/artigos/account-recovery/index.md): An exceptional procedure can redefine trust. - [GitHub Actions: who can change the build tool?](https://thiago.limaesilvatecnologia.com.br/en/artigos/actions-third-party/index.md): Pipeline dependencies deserve code-level scrutiny. - [Security headers: own the final response](https://thiago.limaesilvatecnologia.com.br/en/artigos/headers-ownership/index.md): CDN, proxy and application may produce different settings. - [Infrastructure as code: return manual exceptions to the workflow](https://thiago.limaesilvatecnologia.com.br/en/artigos/iac-drift/index.md): Repositories represent environments only when differences are reconciled. - [Input validation: valid format does not guarantee meaning](https://thiago.limaesilvatecnologia.com.br/en/artigos/input-domain/index.md): Rules must understand the operation's domain. - [BOLA and IDOR: review the actual object](https://thiago.limaesilvatecnologia.com.br/en/artigos/object-authorization/index.md): Knowing an identifier is not authorization evidence. - [JWT: trust extends beyond signatures](https://thiago.limaesilvatecnologia.com.br/en/artigos/jwt-trust/index.md): Each consumer must know which tokens it may accept. - [Key management: plan retirement before rotation](https://thiago.limaesilvatecnologia.com.br/en/artigos/key-retirement/index.md): Changing the active key does not end historical dependencies. - [Kubernetes: namespaces do not finish isolation analysis](https://thiago.limaesilvatecnologia.com.br/en/artigos/kubernetes-tenancy/index.md): Boundaries must account for shared resources. - [Prompt injection: keep authority outside retrieved text](https://thiago.limaesilvatecnologia.com.br/en/artigos/prompt-injection-boundary/index.md): External documents may inform answers without granting permissions. - [Logs: start with the incident question](https://thiago.limaesilvatecnologia.com.br/en/artigos/logging-evidence/index.md): Event volume is not investigation capability. - [MCP: tool changes are trust changes](https://thiago.limaesilvatecnologia.com.br/en/artigos/mcp-tool-change/index.md): An agent's tool catalog needs governance. - [Microservices: preserve decision context when delegating](https://thiago.limaesilvatecnologia.com.br/en/artigos/microservice-delegation/index.md): Technical identity alone does not explain the user's request. - [Multitenancy: extend isolation into the cache](https://thiago.limaesilvatecnologia.com.br/en/artigos/tenant-cache-isolation/index.md): Correct database and API controls cannot fix ambiguous cache keys. - [MFA: track exceptions as carefully as adoption](https://thiago.limaesilvatecnologia.com.br/en/artigos/mfa-exceptions/index.md): High coverage can conceal important alternative paths. - [Segmentation: review permitted outbound traffic](https://thiago.limaesilvatecnologia.com.br/en/artigos/network-egress/index.md): Connection destinations are part of the exposure boundary. - [OAuth: distinguish clients before designing the flow](https://thiago.limaesilvatecnologia.com.br/en/artigos/oauth-client-boundaries/index.md): Mobile apps, browsers and backends have different boundaries. - [Passwords: modernization needs a migration plan](https://thiago.limaesilvatecnologia.com.br/en/artigos/password-migration/index.md): Changing the standard does not update every account. - [Dynamic queries: separate values from structure choices](https://thiago.limaesilvatecnologia.com.br/en/artigos/query-contracts/index.md): Flexible filters need a bounded contract. - [RAG: revocation must reach retrievable content](https://thiago.limaesilvatecnologia.com.br/en/artigos/rag-revocation/index.md): Removing source access may leave usable copies. - [REST APIs: protect operation order](https://thiago.limaesilvatecnologia.com.br/en/artigos/rest-state-machine/index.md): Individually correct endpoints can form an incorrect workflow. - [SAML SSO: rehearse trust changes](https://thiago.limaesilvatecnologia.com.br/en/artigos/saml-certificate-change/index.md): Integrations must survive certificate changes. - [Secrets: emergency rotation must work under pressure](https://thiago.limaesilvatecnologia.com.br/en/artigos/secret-emergency-rotation/index.md): Central storage does not replace rehearsed revocation. - [AI models: record what actually changed in a release](https://thiago.limaesilvatecnologia.com.br/en/artigos/model-release-evidence/index.md): Behavior depends on more than the model file. - [AWS and GCP: turn shared responsibility into tasks](https://thiago.limaesilvatecnologia.com.br/en/artigos/cloud-responsibility/index.md): Assign ownership for each control. - [Code review: prioritize trust-changing modifications](https://thiago.limaesilvatecnologia.com.br/en/artigos/code-review-risk/index.md): Diff size does not measure security impact. - [AI-generated code: acceptance remains an engineering decision](https://thiago.limaesilvatecnologia.com.br/en/artigos/ai-code-acceptance/index.md): Generation speed does not replace behavioral understanding. - [Secure design: defaults are product decisions](https://thiago.limaesilvatecnologia.com.br/en/artigos/secure-product-defaults/index.md): The easiest path often determines actual behavior. - [SSRF: fetching a URL grants network capability](https://thiago.limaesilvatecnologia.com.br/en/artigos/ssrf-fetch-service/index.md): The feature needs destination and behavior boundaries. - [Sessions: interface logout must match access state](https://thiago.limaesilvatecnologia.com.br/en/artigos/session-revocation/index.md): Logout becomes distributed across multiple consumers. - [Supply chain: release the artifact that was assessed](https://thiago.limaesilvatecnologia.com.br/en/artigos/supply-chain-promotion/index.md): Rebuilding at the last step can change the trust unit. - [Threat modeling: end with testable decisions](https://thiago.limaesilvatecnologia.com.br/en/artigos/threat-model-decisions/index.md): Useful diagrams connect threats to actions and owners. - [Transactions: confirmation must represent execution](https://thiago.limaesilvatecnologia.com.br/en/artigos/transaction-integrity/index.md): Users should authorize the parameters producing the effect. - [TLS: review the full path to the data consumer](https://thiago.limaesilvatecnologia.com.br/en/artigos/tls-full-path/index.md): The browser padlock describes only part of the architecture. - [Privacy by architecture: remove unnecessary data](https://thiago.limaesilvatecnologia.com.br/en/artigos/privacy-minimization/index.md): Minimization starts before storage protection choices. - [Vulnerabilities: prioritize the affected-system decision](https://thiago.limaesilvatecnologia.com.br/en/artigos/vulnerability-priority/index.md): Component severity is an input, not the whole context. - [AI agents: define the approval contract before granting autonomy](https://thiago.limaesilvatecnologia.com.br/en/artigos/agentic-security-approval-contracts/index.md): The agent security debate calls for a concrete architecture decision: which changes may an agent execute without approval? ## Optional - [Sitemap](https://thiago.limaesilvatecnologia.com.br/sitemap.xml) - [pt-BR](https://thiago.limaesilvatecnologia.com.br/llms.txt) - [es](https://thiago.limaesilvatecnologia.com.br/es/llms.txt)