Ask any engineering manager whether their team pastes code into ChatGPT and you'll get
a nervous laugh. The honest answer is constantly — a stack trace here, a config file
there, "just cleaning up this SQL." Most of it is harmless. Some of it carries an AWS
key, a database password, or a customer's PII straight to a third-party model.
I've spent the last while looking at how teams try to control this, and most of the






