HD Field Guide 12
Protect secrets with AI coding assistants
Keep credentials, private code and sensitive configuration out of unapproved AI workflows.
Control areaData protection
AudienceDevelopers
Reading time8 min
Reviewed11 August 2026
Coding assistants can accelerate work but prompts, repositories and connectors may expose more than the visible selection.
Minimise context
Share only code required for the task.
Use placeholders for secrets and production identifiers.
Review generated changes
Treat generated code as untrusted until reviewed and tested.
Run security and dependency checks before deployment.
Before you close the guide
- No secrets in prompts
- Repository scope approved
- Generated code reviewed
- Exposure response defined
Continue with primary guidance
Defensive guidance boundary
This guide provides general educational information. Adapt it to your organisation’s policies, contracts, legal obligations and incident process. For an active incident, use trusted professional and official support channels.