You’ve probably been there. You’re evaluating a new AI inference provider. You look at their latency benchmarks. You review their compliance certifications. You sign the SLA. You feel safe. You shouldn’t.
We were recently evaluating Baseten, a heavily funded AI inference provider trusted by major enterprises. Before handing over our production data, we did a “quick check.” You know, just a casual look at their public-facing infrastructure. Twenty-five minutes later, we had admin access to their entire production GitHub environment.
In the AI economy, your most sensitive data isn’t secured by cutting-edge models. It’s secured by whoever manages the vendor’s GitHub tokens.
How did it happen? It wasn’t a sophisticated zero-day exploit or a months-long social engineering campaign. It was a single, long-lived basetenbot token left sitting in a public Harbor project. A credential that granted the exact same level of access as a root administrator.
This is the dark humor of modern infrastructure. We spend millions evaluating AI vendors on model quality, throughput, and brand reputation. Meanwhile, the actual attack surface is a forgotten API key left in a public repository.
A single long-lived bot token in a public repository grants the same access as an admin. No model can outperform a leaked credential.
To their credit, Baseten handled the disclosure professionally and patched the issue quickly. But that’s not the point. The point is the systemic blind spot this exposes. Baseten is a well-funded, serious player. If an outsider can compromise their production environment before lunch, what does that say about the rest of the industry?
It says we are auditing the wrong things. We are mesmerized by parameter counts and latency benchmarks, completely ignoring the fragile chain of credentials that actually holds the entire system together.
We are building trillion-dollar AI economies on top of $10 security hygiene.
If you are building on or evaluating AI infrastructure, vendor due diligence must go beyond PDFs and SLAs. You need adversarial security checks. You need to assume that a vendor’s internal access paths are the weakest link, because your production data will eventually live inside their GitHub permissions.
The true moat of an AI startup isn’t its model. Models are commoditizing by the day. The true moat is operational security. If your vendor can be compromised in 25 minutes by a curious prospect, their model doesn’t matter. Your data is already compromised.
FAQ
Q: Isn't this just an isolated mistake by one company?
A: Not a chance. Baseten is a well-funded provider with major clients. If they can leak a root-level production token in a public repository, it’s a systemic industry blind spot. Everyone is rushing to ship AI features, and credential hygiene is being treated as an afterthought.
Q: What should we actually look for when evaluating an AI vendor?
A: Stop obsessing over latency benchmarks and compliance PDFs. Demand to know their credential rotation policies, how they manage service accounts, and conduct adversarial checks on their public-facing assets. If their GitHub permissions are a black box, your production data is at risk.
Q: Doesn't the fact they patched it quickly prove the system works?
A: Absolutely not. Fast incident response is great, but it doesn't undo the fact that a random prospect found a live admin token in 25 minutes. Relying on the goodwill of outsiders to find your critical vulnerabilities is a terrible security strategy.