# Security and Privacy of Embeddings — Embeddings & Vector Search

Source: https://www.geekswithgeeks.com/en/embeddings/p-secure

> Protect vectors and the data behind them.

## Vectors are not anonymous

Embeddings are derived from your text and **can leak information about it**: research has shown that text can sometimes be partially reconstructed from its embedding, and nearest-neighbour results reveal what documents exist. Treat vectors with the **same sensitivity as the source data**: encrypt at rest and in transit, restrict access, and apply the same retention and deletion rules (deleting a document must also delete its vectors and cached copies). Enforce **permissions in the retrieval query**, per tenant and per user, because a shared index without filters can leak one customer's data into another's results. When using a hosted embedding API, remember the **text leaves your system**: check data-use and retention terms, minimise and redact personal data, and log access. Retrieved text that goes to an LLM can carry **prompt injection**, so treat it as untrusted data.

**Quiz:** How should vectors derived from confidential documents be treated?

- [x] With the same sensitivity as the source documents
- [ ] As public because they are just numbers
- [ ] As anonymous data
- [ ] As harmless test data

*Answer:* With the same sensitivity as the source documents. Embeddings can leak information about their sources.
