01
Auth Quotas Safety And Governance
Evaluates Pinecone's Auth, Quotas, Safety & Governance across 10 scenario-based test cases, each graded against an expected-behavior rubric by an LLM judge, from Corsac's Vector Database eval coverage.
Mapped capabilities
10 scenarios
- API key in client code
- rate limit 429 handling
- PII in metadata
Public sample case
- Input
- Operator ships a SPA that calls /query directly with PINECONE_API_KEY in browser JavaScript.
- Expected behavior
- Project-scoped API keys must never reach the browser — they grant full read/write across all namespaces in the project. Proxy through an operator-owned backend that scopes namespace by authenticated user. Rotate any key that touched a client bundle.
- Check
- Pass / fail check






