Build1 distinct publisher3 min readPublished
A vendor-authored count says a typical production AI app routes through 6 to 9 services, each adding a key, an egress path, an in-runtime SDK, a prompt log and a subprocessor. The count holds up.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Finish the multiplication the post starts. Five obligations per vendor across six to nine vendors is 30 to 45 recurring items [1]: keys with their own rotation stories, egress destinations the firewall has to allow, subprocessor entries on the DPA, breach notification clocks that start independently, dependency trees whose CVE feeds someone is nominally watching [6]. None of that arrived as a decision. It arrived one sprint at a time, according to Backboard.io, which wrote the count [3].
Then count the stack the post itself lists, and the headline range stops holding. Gateway, vector database, memory service, RAG framework, embedding provider, orchestration layer and observability tool is seven categories before you add the two or three model providers, which puts a typical deployment at nine or ten vendors, not six to nine [2]. The company arguing you have too many vendors is undercounting by at least one. Treat 6 to 9 as a floor.
The interesting failure is deletion, and it is a structural one rather than a vendor quality problem. Follow a single user message: it lands in the gateway's request log, a derivative embedding lands in the vector database, the memory service persists a version, and the observability tool captures the whole trace including the completion [8]. That is four retention policies and four deletion semantics behind four vendor APIs, which means an erasure request becomes four tickets rather than one executed operation [9]. Backboard's framing is the right one: under GDPR Article 17, "we asked our subprocessors" is a weaker position than "we called the delete endpoint and logged the result" [10]. The obligation is single and yours; the capability is distributed and mostly not yours.
The escape hatch teams reach for is that embeddings are just numbers, and the cited literature closes it. Morris et al. (2023) demonstrated iterative reconstruction that exactly recovers 92% of short text inputs from their embeddings [5], and Song and Raghunathan (2020) showed embeddings leak content and authorship [c5b]. So the vector store is a second queryable copy of the source data, in a different trust boundary, with its own key, and frequently missing from the data map compliance maintains [7]. Two questions worth asking before any tooling purchase: whether that key is scoped per workload or reads every namespace [15], and whether erasure deletes the embeddings or only the source rows [14].
The in-runtime SDK item on the list is not hypothetical either. LangChain shipped a remote code execution vulnerability in its math chain, CVE-2023-29374 [11], and the integration layer is by definition the code holding credentials to both the model and data layers [4]. Meanwhile the security review goes to the model provider, and the seven services wrapped around it usually get none [13].
Backboard sells AI infrastructure and labels that interest at the end of its own post [12]. The pitch is consolidation, so discount it accordingly. The arithmetic is free, and it is checkable against artefacts you already have: keys in config, allow rules in the firewall, the subprocessor list in the DPA.
Ranked by verification strength, evidence, and original report placement.
A vector database is a second, queryable copy of source data, sitting in a different trust boundary, usually with its own API key, and frequently excluded from the data inventory the compliance team maintains.
Each vendor adds at least five things to the attack surface: a standing API key, an egress path out of the network, an SDK executing inside the runtime, a log store that fills with prompts, and a subprocessor on the data processing agreement.
The AI attack surface has three parts: the model layer (providers prompts travel to), the data layer (systems storing prompts, embeddings, memories or retrieved documents), and the integration layer (every SDK, framework and glue service with credentials to the other two).
Morris et al. (2023), "Text Embeddings Reveal (Almost) As Much As Text", demonstrated iterative reconstruction that exactly recovers 92% of short text inputs from their embeddings.
Song and Raghunathan (2020) showed that embeddings leak both content and authorship.
Eight vendors means roughly eight API keys with their own rotation stories, eight egress destinations the firewall must allow, eight vendor security reviews (or eight skipped), eight subprocessors on the DPA, eight breach notification clocks that can start independently, and eight dependency trees whose CVE feeds someone should be watching.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Verifiable structure, unverified generalizations
The mechanical core is checkable and internally consistent: five per-vendor surface items multiply to about forty for an eight-vendor stack, the four-system deletion fan-out follows from the architecture described, and the security prior art is named and externally traceable (CVE-2023-29374; the December 2022 PyTorch nightly dependency-confusion compromise; two dated embedding-inversion papers with a specific 92% reconstruction figure). What is not evidenced is the population-level framing: 'typical', 'most teams never approved this stack' and 'most stacks fail' rest on no survey, telemetry or sample, and the article's own enumeration counts to 9-10 vendors against a stated ceiling of 9.
No adoption or deployment evidence
The cluster contains no deployment counts, usage disclosures, benchmarks, customer references or pricing data - neither for the sprawling stacks described nor for the consolidation pattern recommended. The two logged observations are historical security incidents in third-party projects, not evidence of adoption of anything in this story, so adoption cannot be scored without guessing.
Modestly overstated by generalization
The article is unusually disciplined for vendor content - it discloses its position up front, and its arithmetic and definitions are verifiable rather than promotional. The overstatement is in scope words: a specific vendor range presented as 'typical' with no sample, 'most teams' and 'most stacks fail' as unmeasured universals, and a headline framing ('every layer is an attack vector') that is stronger than the underlying observation that each dependency adds standing surface. The remedy is also asymmetrically argued: fewer systems is presented as strictly better without weighing concentration, lock-in or capability loss. That yields a small positive gap rather than a large one.
Vendor-authored, disclosed, remedy equals product
Author and beneficiary are the same party: Backboard.io builds AI infrastructure and the piece concludes that the answer is to minimize copies, broker all egress and consolidate the control plane - the shape of a consolidated infrastructure product. That is a strong directional incentive. It is partially mitigated, not removed, by explicit up-front disclosure and by the placement of the labeled position at the end, plus the use of third-party citations (CVE, OWASP, academic papers) rather than product claims for the evidentiary load.
Single self-interested source, no corroboration
One item, one publisher, one interested author, with no independent reporting, no practitioner data and no counter-source in the cluster. Confidence is held up by the checkable pieces - named CVE, named incident, cited papers, reproducible arithmetic - and held down by the absence of any corroboration for the quantitative baseline, the absence of adoption evidence, and the fact that the captured text ends mid-recommendation so the author's full labeled position is not observable.
build
1,500 submissions in 14 days: what a 12th-place GPU kernel says about agent loops1 distinct publisher
build
A twelve-word joke became a discipline, and one seven-step chain had no loop to remove1 distinct publisher
security
A North Korean IT worker got hired by a federal agency. Vetting is a security control now.1 distinct publisher
product
State Department letter would make 35 countries pick an AI side, and the workaround already exists1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 26, 2026