Skip to content

Secrets and Credentials in AI Systems

Keeping API keys, passwords and tokens out of prompts, training data and model reach.

Editorial team 1 min read

AI systems create new ways for secrets to leak.

How Secrets Leak

  • API keys placed in system prompts, which users can often extract.
  • Credentials in code or documents indexed for retrieval.
  • Secrets pasted into chat tools by employees.
  • Environment variables and config files readable by agents.
  • Secrets in logs of prompts and responses.
  • Credentials in training or fine-tuning data, memorised by models.

Good Practice

  • Never put secrets in prompts. Assume system prompts can be revealed.
  • Keep credentials in the application layer, where tools use them without the model seeing them.
  • Scan data for secrets before indexing or training.
  • Restrict agent access to credential files and environment variables.
  • Redact logs.
  • Use short-lived, scoped tokens, so leaks have limited impact.
  • Rotate credentials promptly after suspected exposure.

Employee Guidance

Tell staff not to paste credentials, customer data or confidential code into unapproved AI tools, and provide approved alternatives.

Detect

Use secret-scanning tools on repositories, documents and logs.

More in AI security

All AI security guides →
AI security Guide · 1 min

Introduction to AI Security

What AI security covers — attacks on models, data and AI applications — and how it differs from traditional security.

AI security 1 min read 29 Jun 2025

AI security Guide · 1 min

The OWASP Top 10 for LLM Applications

An overview of the widely used list of the most critical security risks for applications built on language models.

AI security 1 min read 28 Jun 2025

AI security Guide · 1 min

Jailbreaks: How They Work and How to Defend

How people try to get models to bypass their safety training, common techniques, and layered defences.

AI security 1 min read 27 Jun 2025

AI security Guide · 1 min

Indirect Prompt Injection

How attackers hide instructions in web pages, emails and documents that AI systems read, and why it's so dangerous for agents.

AI security 1 min read 26 Jun 2025