Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
World desk6 min

How to Protect Source Code and Secrets When Using AI Coding Assistants

AI coding assistants can see more than the code you paste. Check plan-specific data terms, exclude secrets from context, restrict agent permissions, and review every change.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

You can use an AI coding assistant with proprietary code only after checking what the specific product can access, what it sends and retains, and what its plan permits. Keep live credentials out of prompts and readable project files, limit an agent’s permissions, and review its changes before they run. “Not used for training” does not mean “not transmitted” or “not retained.”

What can an AI coding assistant expose?

Risk depends on the product, plan, interface, feature, and configuration. A tool may receive more than the lines you paste: its context can include conversation history, open or nearby files, workspace content, terminal output, and data from connected tools. For example, Google documents conversation history and snippets from open and adjacent files as possible context for Gemini Code Assist Standard and Enterprise.

Separate four questions before using a tool with a repository:

  • Access: Which files, history, terminal content, or connected services can it read?
  • Transmission: What information is sent to the provider or other services to answer a request?
  • Use: Can prompts, outputs, or feedback be used to improve models, and under what conditions?
  • Retention: What is stored, for how long, and can an organization change that setting?

A “no training” statement answers only the use question. It does not by itself establish that data is never sent, stored, logged, or accessible to the service.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How provider policies differ

The examples below are scoped to the named product and plan, based on the providers’ pages checked October 4, 2026, except Anthropic’s notice, dated March 16, 2026. They are not a universal ranking and should not be extended to other plans, interfaces, or features.

Product and scope Training or improvement Retention and context
GitHub Copilot GitHub says interaction data, including prompts, suggestions, and code snippets, may be used to train and improve models for individual subscribers; individuals can opt out. This statement concerns individual subscribers. For Business and Enterprise, GitHub says prompts and suggestions from IDE chat and code completions are not retained by default; other access paths may retain them for 28 days. Do not apply that distinction to every plan, host, or feature.
OpenAI business products and API platform OpenAI says inputs and outputs from ChatGPT Enterprise, Business, Edu, Healthcare, Teachers, and its API platform are not used for training by default. OpenAI says business data is encrypted in transit and at rest. Qualifying organizations can configure retention, including zero data retention on the API platform. These claims do not cover all consumer services or third-party integrations.
Google Gemini Code Assist Standard and Enterprise Google says it does not use customer data to train models without permission. Google describes the service as stateless and says prompts and responses are not stored in Google Cloud by default; optional Cloud Logging can store inputs and responses. Documented prompt context can include conversation history and snippets from open or adjacent files.
Anthropic Claude Free, Pro, and Max, including Claude Code accounts Anthropic’s March 16, 2026 notice says chats and coding sessions may be used for model improvement if the user opts in, if a conversation is flagged for safety review, or under another explicit opt-in. The notice says feedback may cause the related conversation to be retained for up to five years. It covers consumer plans, not Claude for Work or API terms.

For current details, consult the applicable official pages: GitHub Copilot privacy and responsible use, OpenAI business data, Google Cloud Gemini Code Assist security and privacy, and Anthropic’s model-training notice.

Set rules before connecting a repository

  1. Identify the exact setup. Record the product, plan, interface, model provider, and enabled features. Read the terms for training, retention, logging, feedback, and subprocessors that apply to that combination. Recheck them after a material product change.
  2. Classify the repository. Decide which data classes the tool may handle under your organization’s policies. Regulated, classified, customer, and commercially sensitive data may have contractual or legal constraints; the vendor statements here do not determine whether a particular use is compliant.
  3. Map the assistant’s context. Check what it can read or send: open files, adjacent files, workspace indexing, conversation history, terminal output, extensions, and connected tools. Do not assume it sees only the selected code.
  4. Set a narrow permission boundary. Give it only the files, commands, tools, and credentials needed for the task. Separate read and write access where possible; avoid broad cloud, administrative, SSH, or production permissions.
  5. Choose an execution boundary. For agents that run commands or install dependencies, use a sandbox, dev container, virtual machine, or ephemeral workspace. Restrict outbound network access unless the work requires it.
  6. Keep approval and review in the loop. Require human approval for sensitive actions. Inspect the agent’s actions and resulting diff, especially after it reads external content or changes security-sensitive files.

Keep credentials out of prompts and reachable files

Do not paste live API keys, tokens, passwords, private keys, or production credentials into prompts or assistant-visible terminal sessions. Keep secrets outside project files and use an approved secrets manager or other protected secret store. OWASP advises against hardcoding secrets in repositories or CI/CD configuration and describes ways to detect exposed credentials.

Configure the assistant’s own context-exclusion controls for paths such as .env, private keys, and credential files, then verify that exclusions work for the product and interface you use. .gitignore only controls Git tracking; it does not prevent software running on your computer from reading a local file.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Run secret scanning as part of normal development. If a credential is exposed, revoke or rotate it promptly through its issuer’s process. Deleting a prompt or removing a file from a repository does not prove the credential is unusable.

For practical guidance, see the OWASP Secure Coding with AI Cheat Sheet, OWASP CI/CD Security Cheat Sheet, and GitHub’s documentation on secret scanning.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Constrain agents that can act

An agent that can edit files, execute commands, install packages, or use the network has more authority than a tool that only offers inline suggestions. Match its authority to the task rather than granting broad access for convenience.

  • Use a minimal working copy and least-privilege credentials; do not give a coding agent production access unless the task specifically requires it and policy permits it.
  • Limit command execution and network access. Review package installation and scripts before allowing them to run.
  • Treat issue text, pull-request comments, README files, logs, fetched pages, and tool responses as untrusted input. Such content can contain instructions intended to manipulate an agent.
  • Review changes to dependencies, build scripts, workflows, deployment configuration, and credential access before merging or executing them.

GitHub documents branch and human-review limits for its cloud agent. Those protections apply to that product’s documented workflow; they should not be assumed for other agents.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Review generated code as code from an outside contributor

Keep your existing code review, tests, dependency review, secret scanning, and security scanning. Inspect the complete diff and understand how a change works before accepting or running it. Give particular attention to code that executes in build or deployment paths, where a small change can affect the wider development pipeline.

GitHub advises users to apply the same safeguards and diligence to Copilot output as to other third-party code, including avoiding automatic execution before review. OWASP likewise recommends reviewing agent output and giving heightened scrutiny to build and deployment changes.

Choose a setup against your requirements

Do not choose based on a broad “private” label alone. Compare the exact plan and workflow against the controls your organization needs:

  • Training: Are prompts and outputs used for model improvement by default, by opt-in, or under another stated condition?
  • Retention: What is kept, for how long, through which interface, and can your organization configure it?
  • Context: Can files, snippets, conversation history, terminal output, repository content, or connected tools enter a request?
  • Administration: Does the plan provide the identity, access, audit, and organization-wide settings you require?
  • Agent authority: Can it run commands, use the network, access credentials, alter files, or push changes? What isolation and approval controls are available?
  • Independent checks: Can your workflow retain human review, tests, secret scanning, and code-security scanning?

No cited policy establishes one safest provider or setting for every team. Suitability depends on the organization’s data classification, configuration, and contractual or regulatory requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.