AI coding agents can be made secure for sensitive production code by running them in hardware-isolated virtual machines (using Intel TDX technology) that provide mathematical guarantees that code never leaves a secure boundary, is never stored, shared, or used for training, while still allowing full access to the codebase for development tasks.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
The Secure Way to Code With AI Agents (Zero-Data Retention)
Added:So, if you want to know how to safely run powerful AI coding agents on sensitive production code bases without getting blocked by your security or compliance team, you need to watch this video. Because if you're working in a regulated industry, or honestly, if you just take intellectual property seriously, you've probably realized that tools like Copilot, Cursor, or Cloud Code are not secure and sometimes flat-out banned in some companies. And frankly, you can't blame your security team because sending proprietary source code, secrets, and prompts to a standard third-party cloud is a massive liability. But what if we could give our AI coding agents full access to our code base with a mathematical guarantee that our code is completely isolated, never leaves a secure hardware boundary, and is never stored, shared, or used for training. Today, I'm doing a walkthrough of Origin, the confidential stack for AI agents. I'll show you how to use their web control plane, Origin Studio, and their desktop IDE, Origin CDE, to build secure applications with AI and zero data retention. And thanks to Origin for partnering with me on this video. So, let's understand the core problem that Origin is solving. So, standard AI tools run on software-level container isolation. If the host operating system or a neighboring process gets compromised, your code can be leaked.
Origin handles this by building a confidential stack from the hardware up.
It routes requests through gateways.
They have a confidential AI gateway that supports over 250 LLMs. It routes requests through gateway, their confidential AI gateway supporting over 250 LLMs, and runs execution sandboxes inside hardware-isolated virtual machines.
So, let's see how this works in a real workflow.
So, I'm logged in and I'm going to go to Origin Studio.
So, this is the web control plane for managing your projects, tasks, contacts, and security. So, I'm going to connect one of my GitHub repositories.
And I'll just grant access to my secure vault API.
And then I'll select it.
And now I'll just click deploy.
So, this is a basically a demo Node.js API that handles sensitive cryptographic functions like AES-256-GCM encryption.
The cool thing about Origin Studio is that it doesn't just host your repo. It parses your code base and automatically genera- generates and categorizes tasks.
So, I'm going to click AI task discovery.
And then I'll scan my branch.
And then it's just going to analyze my entire code base and see if there's any tasks that it can help with. And while it's scanning, you can see here's one of the main utility functions within the repo.
And you can see it's generated 13 unique tasks across seven categories. So, let's see what they are.
So, it has an urgent task, securely manage secret key. Uh then it has some high importance tasks.
Add comprehensive unit tests for crypto functions, for testing. We have some security testing. You can see the categories off to the side here. So, it's telling us to download the Origin IDE, which if you don't have it, you should download it now because we're going to use it for the next section.
So, there's different types of categories like documentation, testing, security, features. And these are all really good tasks that we can do on our repo.
So, I'm going to click one of these tasks. Uh validate input for encrypted text format in decrypt functions. And so, it's going to explain the the task.
And then I'm going to go up and click launch CDE. Now, if I do the drop down, we could do the web version, but I'm just going to click the button. And now it's going to actually open up the application that I have installed on my computer.
So, it's saying opening Origin CDE desktop.
Now, I have it up in the the application running on my Mac. This is not the web interface anymore. This is the Mac one.
So, I'm going to click on new work tree.
And Origin isn't just spinning up a standard cloud container. It's It's basically launched a hardware isolated sandbox called a work tree.
This is backed by Intel TDX. That's what it says down here. Uh the TDX sandbox.
So, this means our entire development session runs in an an encrypted virtual machine where memory is cryptographically protected So, even the cloud provider or hypervisor cannot peek into the sandbox or access our code. It's all completely fully isolated. So, I'm going to submit It gave us basically a prompt to submit.
And so, our AI will start working on this code and start implementing um implementing this update to our code.
Now, it's planned that we had that on plan mode before. So, I'm going to go on to build mode. So, it will start actually creating the the actual updates.
So, every model routed through Origin runs with zero data retention by default.
Our code, prompts, and secrets are never stored, share They're never stored.
They're never shared with third parties or even used for model training. So, they're not used by Origin or even by the providers like Anthropic or Open AI.
So, basically a prompt I sent the prompt, the agent securely analyzes the code, it's going to generate the update.
And then it can execute the a test runner directly within our isolated Intel TDX sandbox.
And while it's working, we can check out some of the stuff on the side. So, we can see the repo files, we can see actual actually the code and files in here.
We can close that, but we can also see the task that it's working on, and then we can see the context file, the the context information. So, we can see information like the the model, the limit, the usage, and a bunch of other helpful pieces of information, including everything that's happened so far.
Okay, and it just finished. So, I can click this button here to see all my changes that have happened in the files and that the AI made. And now I can go to the terminal tab at the bottom here, and then I'll just add everything, and then we can commit, and then push.
Basically exactly how you would do in any IDE or terminal. And I can always go into the repo files here, and I can open files directly. So, we can add the code manually, but it's mainly set up for using AI to create the code. And also, the moment the work tree tears down, the hardware encrypted enclave is completely wiped out. There's absolutely no residual data left in the cloud. So, it's a mathematically guaranteed zero-leak life cycle. Origin is built for modern engineering teams and developers who need verifiable compliance without sacrificing AI power.
Get started with the link in the description.
Thanks for watching.
Related Videos

TOP 15 Data compression Interview Questions and Answers 2019 Part-2 | Data compression | Wisdom jobs
wisdomjobs
281 views•2019-06-28

CTS 158: 802.11w Management Frame Protection
ClearToSend
4K views•2019-02-04

NDSS 2019 Send Hardest Problems My Way: Probabilistic Path Prioritization for Hybrid Fuzzing
NDSSSymposium
496 views•2019-04-02

How realistic is Cities: Skylines?
CityBeautiful
159K views•2019-02-14

GUIs & TUIs: Choosing a User Interface for Your Python Project | Real Python Podcast
realpython
2K views•2025-04-04

The OSI Model - Explained by Example
hnasr
225K views•2019-05-12

Cloud Computing - Introduction
elithecomputerguy
98K views•2019-10-07

From Traveler's Dilemma to Dynamic Routing | Demystifying Networking
IITBombayJuly
5K views•2019-08-04
Trending

WOW! Judge TURNS THE TABLES on Trump in His OWN $10B LAWSUIT!!!
MeidasTouch
197K views•2026-07-23

Playstation NO DISC/NO BUY Fight Is Over...
DavidJaffeGames
4K views•2026-07-23

Steam and Xbox Just Dropped The Hammer On PlayStation
OhNoItsAlexx
9K views•2026-07-23

Americans Confused in Australia for 17 Minutes Straight
IWrocker
17K views•2026-07-23