{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"AI Governance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-22","description":"Detect credentials, tokens, private keys, and connection strings in prompts, pasted content, retrieved data, and generated code using pattern- and entropy-based scanning; warn users and block or redact detected secrets before model processing, logging, and storage; guide code-generating systems to reference secret managers and environment variables rather than hardcoding credentials; and store any user-supplied credentials only in a dedicated secret manager encrypted at rest. Retain detection rules, redaction logs, and storage configurations as evidence.","details":{"control_category":"technical","control_type":"preventive","domain":"AI Governance","guidance":[],"members":[{"control_id":"A008","coverage":"full","framework":"aiuc-1","relationship":"equal"}],"statement":"Detect credentials, tokens, private keys, and connection strings in prompts, pasted content, retrieved data, and generated code using pattern- and entropy-based scanning; warn users and block or redact detected secrets before model processing, logging, and storage; guide code-generating systems to reference secret managers and environment variables rather than hardcoding credentials; and store any user-supplied credentials only in a dedicated secret manager encrypted at rest. Retain detection rules, redaction logs, and storage configurations as evidence.","title":"Prevent leakage of credentials and secrets through AI systems","unified_id":"UC-AI-22"},"id":"uc:UC-AI-22","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-22","sourceIds":["aiuc-1"],"sourceUrl":null,"title":"UC-AI-22 — Prevent leakage of credentials and secrets through AI systems","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:029d8c79169be792280d624dfabf7a1ec75b52d06294e2823de1993b005400c3","properties":{},"sourceDetailPath":"/data/v1/records/wf-c66-26a4ed19.json","sourceId":"wf:C66","targetDetailPath":"/data/v1/records/uc-uc-ai-22-129d1e22.json","targetId":"uc:UC-AI-22","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:84b4939370c1ac6f2cf76d4621fcb46c89173633a7b84639cb633431f6170af0","properties":{"control_id":"A008","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-22-129d1e22.json","sourceId":"uc:UC-AI-22","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-a008-509139e6.json","targetId":"ctrl:aiuc-1:A008","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a3d7e648d87833dee50f44a6d87a6c3daadb224ac3ff6d641c02bcb1d77590df","properties":{"rationale":"The same redaction pipeline that catches secrets in logs and outputs also reduces exposure of personal data held alongside them.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-22-129d1e22.json","sourceId":"uc:UC-AI-22","targetDetailPath":"/data/v1/records/risk-ai-privacy-leakage-9aa8d83c.json","targetId":"risk:ai-privacy-leakage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fc4803dec8c99f3805b00e1b4babbf2e8a9ceb9b53d7a23ddee9a4765d47ad09","properties":{"rationale":"Detecting, redacting, and safely storing credentials across prompts, outputs, logs, and generated code is the direct control for secret leakage.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-22-129d1e22.json","sourceId":"uc:UC-AI-22","targetDetailPath":"/data/v1/records/risk-ai-secrets-credential-leakage-abf1bf77.json","targetId":"risk:ai-secrets-credential-leakage","type":"mitigates"}],"schemaVersion":1}
