AI systems create new ways for secrets to leak.
How Secrets Leak
- API keys placed in system prompts, which users can often extract.
- Credentials in code or documents indexed for retrieval.
- Secrets pasted into chat tools by employees.
- Environment variables and config files readable by agents.
- Secrets in logs of prompts and responses.
- Credentials in training or fine-tuning data, memorised by models.
Good Practice
- Never put secrets in prompts. Assume system prompts can be revealed.
- Keep credentials in the application layer, where tools use them without the model seeing them.
- Scan data for secrets before indexing or training.
- Restrict agent access to credential files and environment variables.
- Redact logs.
- Use short-lived, scoped tokens, so leaks have limited impact.
- Rotate credentials promptly after suspected exposure.
Employee Guidance
Tell staff not to paste credentials, customer data or confidential code into unapproved AI tools, and provide approved alternatives.
Detect
Use secret-scanning tools on repositories, documents and logs.