Skip to main content
AI-CONFIDENTIALITY-HABITS5 MIN READ

System Prompts Are Not Vaults

Explain why system prompts should not contain secrets, credentials, or authorization logic.

Do not hide secrets inside instructions. A system prompt can guide model behavior, but it should not hold credentials, private thresholds, internal architecture, or role-permission rules. What belongs outside the prompt Credentials belong in secret management. Authorization belongs in application code. Policy thresholds belong in policy services or governed configuration. Audit decisions belong in logs that humans and systems can review. What the prompt can safely say Prompts can describe behavior without exposing the sensitive rule: use the approved policy service, do not disclose private data, summarize only sources the user is authorized to access, and ask for human approval…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us