<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>ClauLock — blog</title><description>Long-form writing on AI agent security, secrets management architecture, and the Claude Code threat model.</description><link>https://claulock.com/</link><item><title>How to secure Claude agents in production</title><link>https://claulock.com/blog/secure-claude-in-production/</link><guid isPermaLink="true">https://claulock.com/blog/secure-claude-in-production/</guid><description>A practical, end-to-end guide: identity and scoping, never-reveal secrets, tool surface discipline, prompt injection, execution isolation, supply chain, audit, and a concrete incident runbook. Pillar post, ecosystem-neutral where possible.</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate><author>Jesús E. Viera</author></item><item><title>Vault vs ClauLock: why traditional secrets managers fail for AI agents</title><link>https://claulock.com/blog/vault-vs-claulock/</link><guid isPermaLink="true">https://claulock.com/blog/vault-vs-claulock/</guid><description>HashiCorp Vault is the best secrets infrastructure the services era produced — and it&apos;s the wrong shape for agents. A technical walkthrough of where the fit breaks, why the natural retrofits leak, and how the two tools coexist.</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate><author>Jesús E. Viera</author></item><item><title>AI Agent Secrets Management: the category, explained</title><link>https://claulock.com/blog/agent-secrets-category/</link><guid isPermaLink="true">https://claulock.com/blog/agent-secrets-category/</guid><description>A new infrastructure category is forming at the intersection of secrets management and AI agents. Naming it, mapping it, and separating it from the adjacent categories it gets confused with.</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate><author>Jesús E. Viera</author></item><item><title>Claude Secrets Manager: how to stop leaking API keys to your AI agent</title><link>https://claulock.com/blog/claude-secrets-manager/</link><guid isPermaLink="true">https://claulock.com/blog/claude-secrets-manager/</guid><description>Why API keys end up in transcripts when you pair Claude Code with the usual secret-handling patterns, and what it takes to make the leak impossible instead of unlikely.</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate><author>Jesús E. Viera</author></item><item><title>Why .env files are a security liability for AI agents in 2026</title><link>https://claulock.com/blog/env-is-dead/</link><guid isPermaLink="true">https://claulock.com/blog/env-is-dead/</guid><description>.env files solved a problem from 2011. The AI-agent threat model broke every assumption they were built on — here is what replaces them.</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate><author>Jesús E. Viera</author></item></channel></rss>