AI labs hide the model's scratchpad (reasoning), then send you an encrypted copy so the next turn can continue. Public agent logs hid 315,320 of those copies. Cleaning the chat never opens them, and password scanners scored 0. A research paper decoded those copies from 6,708 posted agent sessions. 4.9% of those sessions (328) leaked at least one real secret. We ran five password-style regexes on a fake session that held three long envelopes labeled FAKE. > Chat cleaned, envelope stayed > 64 artifacts never in chat > Writing laptop still holds them We grepped Claude Code and Codex folders used for research and content writing. Counts only. We did not read the blobs. Zero Data Retention still leaves the unread copy on the client. One AWS page calls the same field a hash. What is actually inside that sealed copy? What do you strip before git, evals, or a zip? Does Bedrock make the laptop copy go away? Full Breakdown ↓↓

What is actually inside that sealed copy? Anthropic's docs call that field "an encrypted copy of the full reasoning that you pass back unchanged." OpenAI ships it as encrypted_content when store is false or Zero Data Retention. https://t.co/mzquj3jIg3
Encrypted reasoning fields in transcripts survive chat redaction and defeat regex secret scanners, and the local copies persist on disk even under zero-data-retention — so sharing a session log can leak credentials you believe you removed.
Checking sign-in…
Loading comments…