How secrets leak through AI agents — Venice AI on logs, vaults and blast radius

AI Engineer · youtube · 2026-10-12

At AI Engineer, Venice AI lead DevRel engineer Joshua Mo (former lead maintainer of Rust AI framework Rig) explains why a private model doesn't make a private product: leaks live in the engineering around it.

Privacy philosophy: minimize blast radius — Venice stores no prompts, anonymizes requests to closed providers, runs models in trusted execution environments, and uses split-key encrypted storage.

Leak points: logs quietly capturing prompts and secrets; vault secrets fetched straight into the reasoning layer where one tool call can exfiltrate them.

Defense patterns: hashed IDs instead of personal data; split-key custody; revocable handles; narrow agent scope; a classifier in front of the agent to catch prompt injection; wire the vault to the execution layer, not the LLM; sandboxes plus permission monitoring; confidential compute with verifiable attestations. Confidential tool calls remain an open problem.

Original post →

More from coding & agent

coding & agent channel →