Reference
OWASP Secrets Management Cheat Sheet
The reference answer to how a secret is stored, injected into a running service, rotated and detected when it leaks into code or CI.
Engineering Fundamentals for the Agent Era
API keys or passwords hardcoded in source code or committed to the repository.
Personal data sent to a third-party analytics service or model provider that has no need for it.
Tokens or personal data placed in URLs, where they end up in server logs, browser history and referrer headers.
Test fixtures and screenshots built from real customer data.
Knowing which data is sensitive and which is not, where it travels, and how to keep the sensitive set small.
An agent integrated error tracking by sending each exception's full context, including request headers and form fields, to a third-party service, and put password-reset tokens in the query string of the reset link. Find every place sensitive data now lands outside your control.
Reference
The reference answer to how a secret is stored, injected into a running service, rotated and detected when it leaks into code or CI.
How Meta defines a data-classification taxonomy from the nature of the data and regulatory requirements, then attaches those labels to data so handling rules follow the class.
Demonstrates PII such as social security numbers being extracted from LLM and RAG systems, the newest leak path: sensitive data copied into prompts, embeddings and vector stores.
An engineer's guide to classifying data by privacy risk, cataloging where it lives, controlling what is shared with third parties, and building deletion into the architecture.
Covers data governance, pseudonymization and anonymization, and building privacy into data pipelines, so you can minimize what sensitive data flows downstream.
Reference
NIST's method for identifying PII and assigning each field a confidentiality impact level, which supports the classify-every-field competency.