Models & policy

Secrets

Secret protection reduces accidental exposure to a model. It does not turn source files, prompts, or transcripts into a secret store.

Settings

secrets.moderedact replaces values; obfuscate preserves reversible placeholders inside the local runtime.
secrets.minLengthMinimum discovered value length; default 8.
secrets.discoverEnvironmentProtect values from secret-named environment variables; default true.

Boundary

  • Never commit credentials to project configuration or context files.
  • Do not paste private keys, session cookies, or access tokens into prompts.
  • Use the platform secret store for operator and control-plane credentials.
  • Review exported sessions before sharing them outside the trusted boundary.

Limitations

Automatic discovery depends on known values and secret-like names. It cannot reliably classify every sensitive business value. Workspace and network isolation remain necessary for high-risk data.

Stay in the loop. Never miss out.

Subscribe to our newsletter and unlock Wisent insights.