Pages
Policy Config — Credential Protection

Source: c65 policy-definitions.md P8 — detector-list shape

‹ Policy Catalog

Credential Protection

Secrets and credential files stay out of model context — reads of key material into an agent are detected at file open.

Data Protection
high
P8
SatisfiesOWASP LLMATLASAI RMFCSF 2.0ISO 27001SOC 2EU AI ActHIPAAGDPR
Underlying control— show
file: severity in (high, medium)edit as custom control →

Protected path categories

Detectors toggle individually; hit counts are the last 24h.

Credential files

high
17 hits
high
9 hits~/.aws, ~/.gcloud, ~/.azure
high
0 hits
medium
4 hits
medium
2 hitsnoisy on dev machines

Exceptions

Scoped carve-outs with a reason and an expiry — accepted risk, on the record.

ScopeValueReasonExpires
agentsecrets-rotatorThe rotation agent must read key material by designnever

Remediation shown on findings: Rotate the exposed secret; exclude the path from agent reach.

Qpoint Brand Style Guide