Preventing AI Code Scanners from Leaking Credentials in CI/CD
How automated PR review bots, LLM security scanners, and CI/CD pipelines handle secrets, environment variables, and build artifacts.
What AI coding assistants and chatbots do with what you feed them: retention windows, training opt-outs, sub-processors, and how consumer terms differ from enterprise ones.
How automated PR review bots, LLM security scanners, and CI/CD pipelines handle secrets, environment variables, and build artifacts.
How Zero Data Retention (ZDR) works in enterprise AI APIs, memory scrubbing, audit logs, and provider compliance comparison.
Cursor's privacy policy states no retention period and never mentions Privacy Mode. What Anysphere commits to on training, and the gap between documents.
On individual Copilot plans, training on your data is on by default since April 2026. What the docs say, which models see your code, and what to change.
How to prepare auditor evidence, control mapping, and vendor oversight documentation for AI assistants in a SOC 2 Type II assessment.
Practical techniques to prevent API keys, database credentials, and tokens from being transmitted to AI tools via context buffers and prompts.
How Retrieval-Augmented Generation architectures leak sensitive data across tenant boundaries, and how to implement vector security.
How to mitigate OWASP LLM06 Excessive Agency when deploying AI agents with shell, database, API, and web browsing tool capabilities.
A security engineer's checklist for AI coding tools: what to establish about retention, training use and sub-processors before your code leaves.
How proprietary code transmission to AI assistants intersects with confidentiality agreements, trade secrets, and client contracts.
How consumer, pro, team, and enterprise AI tiers differ on training opt-outs, prompt retention, data residency, and legal liability.
A plain-language guide to the OWASP Top 10 for Large Language Model Applications, covering prompt injection, data poisoning, and model denial of service.
Why an AI assistant that reads untrusted content can be turned against you, what it can and cannot be tricked into, and the mitigations that actually hold.
AI assistants in your editor transmit surrounding context, not just your prompt. What gets collected, how secrets leak, and the exclusions to configure.