Hide Your Keys (Your Secrets Manager Doesn't)
In this video
What you'll learn
Where your credentials live
Trace one credential from vault to agent. Does your agent hold the live key or does something else?
Your agent's scope
Evaluate what your key can actually do and how many agents share it. Would you give a day-one hire that level of access?
Credential Exposure Map
Map one agent's full credential chain: location, scope, sharing, exposure level. Gain access to exposure mapping tool.
Why this topic matters
You did the right thing: you moved your keys into a secrets manager. Then your coding assistant read your .env and printed a live key straight into the chat, despite the rule telling it not to. "Your manager solved a real problem- it got the key out of your code. What it did not do is get the key out of your agent. At runtime, your agent is still holding it. We'll also show you the latest tools.
You'll learn from
Jess Stahl, DBH
Founder/CEO @ Secure AI Lab. AI Governance, Risk, & Compliance Expert
Directed "first-ever" AI and privacy tech pilots @ U.S. federal government, Vice President & CDO @ institutional accreditor, SME consultant for inter/national privacy tech and AI integration initiatives.
Curtis Mitchell (CISSP, CIPT)
Privacy Engineer & Security Expert
Engineer with 15 years experience: early stage startups in Silicon Valley -> NASA / Census Bureau -> independent consultant
Trusted by...
Go deeper with a course
Build a Reliable AI Business: Secure Agents


Jess Stahl, DBH and Curtis Mitchell (CISSP, CIPT)
Founder/CEO @ Secure AI Lab. AI Governance, Risk, & Compliance Expert. Privacy Engineer & Security Expert
Keep exploring



