HD Field Guide 12

Protect secrets with AI coding assistants

Keep credentials, private code and sensitive configuration out of unapproved AI workflows.

Control area
Data protection
Audience
Developers
Reading time
8 min
Reviewed
11 August 2026
Control areaData protection AudienceDevelopers Reading time8 min Reviewed11 August 2026

Coding assistants can accelerate work but prompts, repositories and connectors may expose more than the visible selection.

Minimise context

Share only code required for the task.

Use placeholders for secrets and production identifiers.

Review generated changes

Treat generated code as untrusted until reviewed and tested.

Run security and dependency checks before deployment.

Completion check

Before you close the guide

  • No secrets in prompts
  • Repository scope approved
  • Generated code reviewed
  • Exposure response defined

Trusted references

Continue with primary guidance

Defensive guidance boundary

This guide provides general educational information. Adapt it to your organisation’s policies, contracts, legal obligations and incident process. For an active incident, use trusted professional and official support channels.