惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
D
DataBreaches.Net
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
The GitHub Blog
The GitHub Blog
Blog — PlanetScale
Blog — PlanetScale
Microsoft Security Blog
Microsoft Security Blog
A
About on SuperTechFans
Vercel News
Vercel News
L
LangChain Blog
B
Blog RSS Feed
Y
Y Combinator Blog
IT之家
IT之家
H
Hackread – Cybersecurity News, Data Breaches, AI and More
GbyAI
GbyAI
V
V2EX
博客园 - 三生石上(FineUI控件)
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
阮一峰的网络日志
阮一峰的网络日志
有赞技术团队
有赞技术团队
D
Docker
V
Visual Studio Blog
aimingoo的专栏
aimingoo的专栏
Last Week in AI
Last Week in AI
月光博客
月光博客

Blog on 1Password Blog

Why secure-by-design is an incentives problem, with Bob Lord | 1Password NIST and AI agents: 1Password’s approach to agent identity | 1Password Go beyond device health with External Checks in 1Password Device Trust | 1Password Natoma and 1Password help enterprises scale AI securely with governed agent access | 1Password New integrations between 1Password SaaS Manager and EPM | 1Password A first step toward post-quantum security | 1Password RSA 2026: Leading the way to secure agentic AI | 1Password How 1Password is Building a Culture of AI Fluency Through AI Champions | 1Password 1Password vs. Keeper Security: A comparison | 1Password 1Password vs. LastPass: Which is right for you? | 1Password Secure MCP credentials with 1Password and Runlayer | 1Password The next layer of AI security | 1Password Building the next chapter of Go-to-Market in EMEA | 1Password Automating SOC workflows with 1Password Enterprise Password Manager | 1Password Automated Provisioning hosted by 1Password: A Simpler, Smarter Way to Manage Access | 1Password Introducing 1Password® Unified Access: Identity Security for Humans and Their AI Agents | 1Password Next-generation automated provisioning, without compromising zero-knowledge security | 1Password Bitwarden vs. 1Password: Which password manager is right for you? | 1Password Password Manager for Families, Enterprise & Business | 1Password | 1Password How to wrangle SaaS contract renewals | 1Password Stop trusting consumer browsers with work credentials | 1Password IAM stops at sign-in. Your credentials do not. | 1Password Your digital pit crew: a 10-minute pre-race security checklist | 1Password 1Password Device Trust is coming to EMEA | 1Password The identity transformation: Analyst and CIO insights | 1Password Why now is the moment to join 1Password Go-To-Market | 1Password Identity and Accountability in the Age of AI Agents | 1Password How 1Password secures agent architectures | 1Password 1Password becomes the first global partner to transact through Express Private Offers in AWS Marketplace | 1Password Start Learning on 1Password Academy | 1Password
The security principles guiding 1Password’s approach to A...
info@1password.com (Jacob DePriest) · 2025-08-07 · via Blog on 1Password Blog

AI is transforming the way we work. There are immense opportunities for automation, intelligent decision-making, and productivity gains. This transformation is a tremendous opportunity, but it also comes with tremendous responsibility, especially when security is involved. For example, AI systems can now act on behalf of users, access sensitive data across tools, and make decisions without oversight, all of which have security implications.

Building AI you can trust

One broader principle we embrace at 1Password is the “principle of yes.” It’s the idea that security must enable individuals and employees to do their jobs. This underlying principle is also true of AI agents. Our goal is to enable AI agents to do what they’re designed to, but in a way that is trustworthy, secure, and follows best practices.

At 1Password, we strive to make security effortless and universal. When it comes to AI, that means enabling organizations to use AI tools effectively without compromising our core security values of privacy, transparency, and trust.

As we empower our customers to securely adopt AI, we are building around a clear set of principles. Below are the security principles that will guide how we build, adopt, and integrate AI—today and in the future.

Secrets stay secret

Encryption is the foundation of our trust model. Any interaction involving credentials must preserve 1Password’s zero-knowledge architecture, no exceptions.

Authorization must be deterministic, not probabilistic

LLMs are not authorization engines. While they can assist in interpreting user intent, access decisions must be governed by predictable, rule-based flows.

Furthermore, users should see a deterministic auth prompt that they know instead of a multi-interpretable chat message (where the LLM may even fool you asking for X while you're granting access to Y). Users must always see exactly what they are granting access to and this should be done with a deterministic "system level" method by a trusted party (e.g. your OS or 1Password) as opposed to non-deterministically in-chat.

Raw credentials should never enter the LLM context

LLMs operate in untrusted inference environments, with open-ended context windows and memory. Raw secrets have no place in prompts, embeddings, or fine-tuning data.

Auditability must be taken into account

Every action involving credential access, by a user or an AI agent, should leave an audit trail. Given that AI agents are capable of taking action and may have access to sensitive data, it is imperative that organizations have visibility into that access, what actions took place, and the context around the approval for the agent to take that action.

Show what AI can see – and what it can’t

Users deserve clarity about how AI is used in 1Password products, including what data is accessed, when, and why.

Least privilege and minimum exposure by default

Agentic systems must follow the same access discipline we expect of humans: only what’s needed, only when needed.

Security and usability are co-requirements

Security is only effective if it’s usable. Our goal is to build secure-by-default experiences that feel intuitive for users working with or through AI.

1Password & Security-first AI

Security is not a bolt-on at 1Password. It’s built into everything we do. And we’re taking the security of AI very seriously as we continue to deliver best-in-class access management. This is something we reflected in a recent blog post on why we won’t expose raw credentials via MCP. This is also why existing approaches of using separate, siloed tools around privileged access and secret management no longer work; these concepts need to be unified into a common scheme around user and agentic AI access management.

As we bring the power of AI into our platform, these principles ensure that innovation never comes at the expense of trust. We believe the use of AI must be private, transparent, and secure by default—and we’re making it so.