3 ms·
And none of the LLM providers can do this themselves? I can’t just point Claude at a GitHub repo and ask it to check it for me?
by bix6 26d ago
And none of the LLM providers can do this themselves? I can’t just point Claude at a GitHub repo and ask it to check it for me?
- nandakishor_ml 26d agonot without sending your code to them, if you have .env file with variables exposed, you will need to rotate again.
- bix6 26d agoOk and? Nobody actually cares to pay for security unless it’s mandated. Why would someone spend money on your unknown code review tool when the LLM provider the company has already approved can do it?
- nandakishor_ml 25d agoHealthcare btw and also the llm that done the code is bad at review and if you do write code people who don't want to send credentials to cloud
- bix6 25d agoRight well good luck.
- alchemism 25d agoThat’s not how enterprise data controls operate in e.g. AWS Bedrock or Databricks - where they use models - sorry to inform you.
- nandakishor_ml 23d agoYou do need to sign DPA with them
- alchemism 22d agoYes, it would typically be done under contract and then implemented as compliance policy across the enterprise cloud - it would not be up to a tenant to arrange a ZDR policy. Also, the models are shipped to big platforms to run as an executable on their hardware. Except in certain cases like Anthropic Fable. In true enterprise you’d want a compliance office product before an engineering office product…