Skip to main content

Security and data

Credentials

Use a dedicated, restricted customer credential for evaluation. The plan names its environment variable; export the value locally or provide it through the approved secret path. Never put a credential value in:
  • CLI arguments;
  • evaluation plans;
  • prompts or chat;
  • source control;
  • issues, pull requests, or support requests.

Candidate and evidence

Intermesh preserves the inspected candidate and evaluation artifacts in the workspace. Treat plans, prompts, traces, answers, and results as customer data. Limit allowed hosts to the target services the evaluation needs. Do not use a broad production credential or unrestricted network access.