logoalt Hacker News

nullcathedraltoday at 4:32 PM2 repliesview on HN

Do you run a dedicated "AI SRE" instance for each customer or how do you ensure there is no potential for cross-contamination or data leakage across customers?

Basically how do you make sure your "AI SRE" does not deviate from it's task and cause mayhem in the VM, or worse. Exfiltrates secrets, or other nasty things? :)


Replies

baileywickhamtoday at 4:43 PM

We run a dedicated AI SRE for each instance with scoped creds for just their instance. OpenClaw by nature has security risks so we want to limit those as much as possible. We only provision integrations the user has explicitly configured.

webpolistoday at 6:33 PM

[dead]