When memory is permanent, a remembered secret can never be deleted. This is the 73-day record of the automated gate that stands at the last moment prevention is possible: the volume decomposed to its actual sources, every gap in our own record disclosed in our own ink. Siblings: the energy receipts · the team receipts.
The counts come from the gate's own append-only verdict ledgers, measured by scripts with a safe-field whitelist: no secret material, message bodies, previews, or content values were ever read into any output. Raw block counts are inflated by auto-save retries of stuck payloads, so rather than lean on a headline number the study decomposes the volume to its actual sources (deduplicated by the content-hash fingerprint the ledger records). The study states plainly where the record has gaps: the ledgers begin May 4, 32 percent of rejects were observe-mode before enforcement flipped on June 17, one scanner blind spot was found by our own review in June and closed the same day with a test, and the chronic file that dominates the raw counts is a likely false positive. Honest numbers survive hostile review; that is the whole method.
How often does an AI working session try to memorize a secret, and what does it take to stop that when memory is permanent?
Indelible receipts series · trust leg · siblings: indelible.one/energy (the cost of forgetting) · indelible.one/team (the yield of remembering). Rebuilt 2026-07-16 from a fresh recount of the gate's own ledgers, deduplicated by the content-hash fingerprint the ledger records (an earlier draft used a looser proxy; this version supersedes it).
Indelible stores AI working sessions encrypted, permanently, on the BSV blockchain. Permanence is the product, and permanence is also the hazard. A private key, an API token, or a wallet seed etched into an immutable chain can never be deleted, redacted, or expired by anyone. The only remedy left afterward is rotating the secret itself. So the moment before broadcast is the last moment prevention is possible.
This study measures the real ledgers of the automated gate that stands at that moment: how often working sessions carried credentials toward permanent storage, what got blocked, where the volume actually came from, and what the honest limits of the record are.
The Witness is a pre-broadcast security review that inspects every save before it can be written to chain. Today it is the second layer of a two-layer design. Layer 1, redact: a regex scrubber (Anthropic, OpenAI, AWS, WIF, GitHub, Telegram, PEM patterns, with Base58Check validation to reject wallet-key false positives) strips credential-shaped strings from every session sink before encryption, so a credential-bearing session saves clean instead of stalling. Layer 2, block: the Witness re-scans the payload as the fail-safe; if the scrubber ever misses a sink, the gate hard-blocks the save. The pair is designed so its worst failure mode is a stalled save, never an etched plaintext key. The scrub layer was completed in late June; the timeline in section 4 is exact about what the gate did and did not do before that. Every verdict is appended to a local ledger, which is the raw material of this study. The gate rule itself was born from a real near-miss: on 2026-05-02 an Anthropic API key reached a save payload through a tool-result dump and was caught manually; the content-scan rule shipped the next day, and the ledger begins the day after that.
Of 15,733 raw credential findings, 15,618 (99.3 percent) are BSV wallet private keys. Telegram bot tokens account for 105, Anthropic API keys for 10. No other scanner type ever fired. This matters because a wallet key is precisely the credential class where an immutable leak is unrecoverable: you cannot rotate the coins, only try to move them before someone else does.
Raw block counts are the wrong headline, and rather than bury that we decompose it to the source. The 5,741 credential rejects break into two populations:
| Population | Rejects | Distinct sources | What it is |
|---|---|---|---|
| File saves | 3,430 | 20 distinct file paths | 19 of them were blocked exactly once: clean, one-time near-misses, each caught and gone. The 20th is a single chronic file blocked 3,411 times across 68 days. |
| Session saves | 2,311 | 1 stuck condition | the documented June stall (Jun 16 to 25): a session save that could not complete, re-blocked on every auto-save retry. |
So the genuinely distinct signal over 73 days is 19 one-time file near-misses plus one chronic file plus one stall incident. The other roughly 5,700 rejects are those same two chronic conditions counted again on every retry. We do not claim thousands of distinct secrets, and we do not claim a tidy small number either; the ledger fingerprints the payload, not the secret inside it, so the honest unit is distinct sources, and there are about twenty.
On 2026-06-25 our own adversarial review of the continuity fix (workflow continuity-fix-verify) found a scanner blind spot: a wallet key placed in a session's structured_context.todos field was not covered by either layer. It was closed the same day, in the same change, with a regression test that now asserts a WIF in that field cannot reach chain (redact-session.test.mjs, the test named "MF-1"). This was a coverage gap caught in review and fixed before release, not a live broadcast. We surface it because a detector can only witness the sinks it scans, and showing the blind spot we found is more honest than claiming there were none.
Where no gate stands, the record is grim, and verified at the primary source (GitGuardian, State of Secrets Sprawl 2026, published March 2026):
Over 73 measured days, an automated gate caught 5,741 save attempts that carried credentials toward permanent, immutable storage. 99.3 percent of what it caught were wallet private keys, the one credential class an immutable leak can never take back. Decomposed honestly, the volume is dominated by two recurring conditions, a single chronic file and one stalled session, with 19 further one-time near-misses from distinct files; the gate hard-blocked once enforcement began, its bypass has never been used, no known plaintext credential has ever reached the chain, and the one scanner blind spot in the record is one our own review found and closed with a test. In the outside world, where no such gate stands, the same class of mistake put 28.65 million secrets on public GitHub last year, up 34 percent, most of which will never be rotated. When memory is permanent, the only good remediation number is the one this ledger shows: caught at the door, before it could be remembered.
Every number traces to a fresh script recount of the reject ledger (reconciliation, hash dedupe, type split, enforcement posture) and to primary-source verification of the GitGuardian 2026 figures. Raw counts are decomposed to distinct sources rather than reported as distinct secrets; estimates and false-positive suspicion are labeled; the June stall and the chronic file, together roughly 99 percent of raw volume, are broken out, not buried.