AI governance for Codex
Codex security: redaction and visibility
PromptWall redacts secrets, credentials and personal data in every Codex prompt before it reaches OpenAI, in the Codex CLI and the Codex desktop app signed in with ChatGPT.
Real usage
What people paste into Codex
The patterns we see most often once a team adopts Codex for real work.
Credentials pasted into a task
A developer hands Codex a failing script together with the real keys and passwords it uses, copied from a terminal or a config file.
Repo context sent with each task
Codex reads project files to complete a task, so .env files, test fixtures and seed data can travel with the prompt.
Customer data in logs and samples
Log excerpts and sample records pasted for a fix often include real names, emails and phone numbers.
What your employee typed
Fix the nightly export job. It connects with postgres://etl_user:[email protected]:5432/orders and emails [email protected] on failure.
What Codex received
Fix the nightly export job. It connects with [CONNECTION_STRING_1] and emails [EMAIL_1] on failure.
Coverage
How NexusNest covers Codex
PromptWall
- API keys, tokens, passwords and connection strings in prompts and code context
- Names, emails, phone numbers and other personal data in logs and fixtures
- Internal admin emails and other confidential identifiers inside repo files
NetLens
NetLens shows how the team uses Codex and how often PromptWall redacted something, built from redacted text only, never from anyone's raw prompts.
Learn moreFAQ
Codex, common questions
Which Codex setups are covered?
The Codex CLI and the Codex desktop app when they are signed in with ChatGPT. Prompts are redacted before they reach OpenAI.
Does it work on macOS and Windows?
Yes. The NexusNest agent runs on both and covers Codex at the device level.
What does Codex see instead of my secret?
A labelled placeholder such as [API_KEY_1] or [PASSWORD_1]. The task still reads naturally, so Codex can reason about the code around it.
Does redaction ever block a developer?
No. If redaction cannot run, the request goes through. The event is tagged with its reason, audited and shown to admins as an alert.
Start with one team. Prove control before you scale AI.
Start with one team. See exactly how your company uses AI.