Wednesday, September 9, 2026
1 change · saas-18.3
Security fixes and vulnerability patches
Neutralized database copies will no longer retain real OpenAI or Google API keys. This prevents copied databases from making AI provider calls using a customer’s credentials, reducing the risk of unintended usage or exposure.
Original PR description
Currently if you were to get a dupe of a database with credentials for either OpenAI or Google, the api keys will be present in the neutralized database. This is problematic because API calls can still go through with the client's credentials