unified

UC-AI-22 — Prevent leakage of credentials and secrets through AI systems

Detect credentials, tokens, private keys, and connection strings in prompts, pasted content, retrieved data, and generated code using pattern- and entropy-based scanning; warn users and block or redact detected secrets before model processing, logging, and storage; guide code-generating systems to reference secret managers and environment variables rather than hardcoding credentials; and store any user-supplied credentials only in a dedicated secret manager encrypted at rest. Retain detection rules, redaction logs, and storage configurations as evidence.

In catalog since 2026-09-17T22:28:00Z · Last changed 2026-09-17T22:28:00Z (f368a6cce277)

Record JSON · Open in map · Data retrieval guide

Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.

Attributes

domain
AI Governance
type
preventive
category
technical

Details

unified_id
UC-AI-22
title
Prevent leakage of credentials and secrets through AI systems
statement
Detect credentials, tokens, private keys, and connection strings in prompts, pasted content, retrieved data, and generated code using pattern- and entropy-based scanning; warn users and block or redact detected secrets before model processing, logging, and storage; guide code-generating systems to reference secret managers and environment variables rather than hardcoding credentials; and store any user-supplied credentials only in a dedicated secret manager encrypted at rest. Retain detection rules, redaction logs, and storage configurations as evidence.
domain
AI Governance
control_type
preventive
control_category
technical
members
  • framework
    aiuc-1
    control_id
    A008
    coverage
    full
    relationship
    equal
guidance

    Source

    No record-specific source URL is provided.

    Connections