How secrets leak through AI agents — Venice AI on logs, vaults and blast radius
AI Engineer · youtube · 2026-10-12
At AI Engineer, Venice AI lead DevRel engineer Joshua Mo (former lead maintainer of Rust AI framework Rig) explains why a private model doesn't make a private product: leaks live in the engineering around it.
Privacy philosophy: minimize blast radius — Venice stores no prompts, anonymizes requests to closed providers, runs models in trusted execution environments, and uses split-key encrypted storage.
Leak points: logs quietly capturing prompts and secrets; vault secrets fetched straight into the reasoning layer where one tool call can exfiltrate them.
Defense patterns: hashed IDs instead of personal data; split-key custody; revocable handles; narrow agent scope; a classifier in front of the agent to catch prompt injection; wire the vault to the execution layer, not the LLM; sandboxes plus permission monitoring; confidential compute with verifiable attestations. Confidential tool calls remain an open problem.
More from coding & agent
- AI-era coding interview: hand candidates a broken agent-built app and watch them debug — gethackteam · 2026-10-12
- Visualizing parallel requests with TQDM: watch multiple queues grow in real time — AnuranBuilds · 2026-10-12
- Running all your coding agents through a Grok bot: parallel Claude Code PR pipeline — Rasmic · 2026-10-12
- Running GLM-5.3-Flash on dual Ascend 310P cards: 8-9 tok/s and 311K context — matteiuspi · 2026-10-12
- plain writing is the team's single most-used internal skill, by a factor of 2 — sh_reya · 2026-10-12
- plain-writing-skill: an open-source skill that makes AI agents write plainly — sh_reya · 2026-10-12