Pages
Policy Config — Credential Protection
Source: c65 policy-definitions.md P8 — detector-list shape
‹ Policy Catalog
Credential Protection
Secrets and credential files stay out of model context — reads of key material into an agent are detected at file open.
Data Protection
high
P8Satisfies
OWASP LLM
ATLAS
AI RMF
CSF 2.0
ISO 27001
SOC 2
EU AI Act
HIPAA
GDPR
Underlying control— show
file: severity in (high, medium)edit as custom control →Protected path categories
Detectors toggle individually; hit counts are the last 24h.
Credential files
high
17 hitshigh
9 hits~/.aws, ~/.gcloud, ~/.azurehigh
0 hitsmedium
4 hitsmedium
2 hitsnoisy on dev machinesExceptions
Scoped carve-outs with a reason and an expiry — accepted risk, on the record.
| Scope | Value | Reason | Expires | |
|---|---|---|---|---|
| agent | secrets-rotator | The rotation agent must read key material by design | never | |
Remediation shown on findings: Rotate the exposed secret; exclude the path from agent reach.