Lesson 23 / 28

Security and Privacy of Embeddings

Protect vectors and the data behind them.

Vectors are not anonymous

Embeddings are derived from your text and can leak information about it: research has shown that text can sometimes be partially reconstructed from its embedding, and nearest-neighbour results reveal what documents exist. Treat vectors with the same sensitivity as the source data: encrypt at rest and in transit, restrict access, and apply the same retention and deletion rules (deleting a document must also delete its vectors and cached copies). Enforce permissions in the retrieval query, per tenant and per user, because a shared index without filters can leak one customer's data into another's results. When using a hosted embedding API, remember the text leaves your system: check data-use and retention terms, minimise and redact personal data, and log access. Retrieved text that goes to an LLM can carry prompt injection, so treat it as untrusted data.

Quick check: How should vectors derived from confidential documents be treated?

  • With the same sensitivity as the source documents
  • As public because they are just numbers
  • As anonymous data
  • As harmless test data
Answer

With the same sensitivity as the source documents — Embeddings can leak information about their sources.