Glossary · Security & governance
Data Exfiltration
Unauthorized transfer of protected data from a system or trust zone to a person, tool, service, or storage location that is not permitted to receive it.
Why it matters
An agent can expose secrets through generated text, tool arguments, URLs, logs, or side effects even when the original data store remains intact.
In practice
Minimize readable data, allowlist destinations, inspect outbound tool calls, redact sensitive fields, and alert on unusual transfers across trust boundaries.
Common confusion
Exfiltration is about unauthorized movement or disclosure. Ordinary retrieval of data by an authorized component is not exfiltration, although later use can become one.
Related terms
Sources
Browse the learning paths to see this term in context — every lesson is free to read.