Glossary · Security & governance

Data Exfiltration

Unauthorized transfer of protected data from a system or trust zone to a person, tool, service, or storage location that is not permitted to receive it.

Why it matters

An agent can expose secrets through generated text, tool arguments, URLs, logs, or side effects even when the original data store remains intact.

In practice

Minimize readable data, allowlist destinations, inspect outbound tool calls, redact sensitive fields, and alert on unusual transfers across trust boundaries.

Common confusion

Exfiltration is about unauthorized movement or disclosure. Ordinary retrieval of data by an authorized component is not exfiltration, although later use can become one.

Related terms

Sources

Browse the learning paths to see this term in context — every lesson is free to read.