Cover Image for Securing Your Coding Agent: The Road to the Software Factory
Cover Image for Securing Your Coding Agent: The Road to the Software Factory
Avatar for Insecure Agents
Presented by
Insecure Agents
70 Going

Securing Your Coding Agent: The Road to the Software Factory

Registration
Welcome! To join the event, please register below.
About Event

Your coding agent has more access than you think. It's running with your credentials, your .env file, and reaches into every repo that the host can touch and when it ships code, that code goes out faster than anyone can review it.

Everyone's talking about the software factory: agents running loops, shipping code unattended while you sleep. The factory demands three things at once: security, capability, and autonomy, but most teams are stuck with impossible tradeoffs that prevents them from achieving all three. Lock the agent down and you kill its capability and autonomy; that's what consent fatigue really is, clicking "yes" on autopilot until you stop reading. Unleash it and you've handed long-lived secrets to a process you can't attribute or halt.

That trilemma is a false choice. There's an architecture that gives an agent real autonomy inside a governed boundary and securing the coding agent turns out to be the prerequisite for the factory, not an afterthought to it.

At Black Hat, Insecure Agents is hosting a panel where we’ll cover best practices for securing your coding agent featuring a new reference architecture from Snyk, Docker, and Keycard that provides a single governed boundary every agentic action crosses, from identity to sandbox to supply chain.

Keycard — issues short-lived, resource-scoped credentials the agent never actually holds, and binds every action back to a human principal.

Docker — provides throwaway micro-VM sandboxes with default-deny egress, so a runaway agent has nowhere to reach.

Snyk — provides software verification and protects your software supply chain

Moderated by Allie Howe, host of the Insecure Agents Podcast.

What we'll get into:

  • The security, capability, autonomy trilemma and the architecture that stops it from being a two-out-of-three choice

  • Why sharing one API key across your agent fleet quietly kills attribution and what per-action identity looks like instead

  • Sandboxing best practices: micro-VMs, default-deny networking, and credentials the agent never sees

  • Securing the agent supply chain, from AI-BOMs to the code your agent just wrote

Built for the engineers and security leads who are using or governing coding agents and want to run them without holding their breath.

Location
Las Vegas Strip
NV, USA
Avatar for Insecure Agents
Presented by
Insecure Agents
70 Going