Address OWASP LLM02:2025 Sensitive Information Disclosure + Privacy and Lawful Basis for LLM Processing. Sensitive Information Disclosure occurs when LLM systems disclose training data + user data + system data including PII + credentials + intellectual property + trade secrets to unauthorised parties via memorisation + leakage + inference + side-channel attacks. Mitigations include (a) classify data flowing into + through LLM systems + apply appropriate protection per classification + (b) implement data minimisation in training + fine-tuning + retrieval + (c) implement differential privacy + sanitisation + redaction for training data + (d) implement access controls + output filtering against unauthorised disclosure + (e) implement appropriate legal basis + consent + DPIAs for personal data processing per applicable regulation (GDPR + CCPA + APPI + similar) + (f) maintain data subject rights handling including erasure consideration for trained models.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.