Path 03Lesson 1 / 6

Define where your data can go

Trace data through the development tool, model, logs, and deployed service. Verify the boundary before using confidential information.

Foundation10 minReviewed

Published by How we write

What you will learn

  • Distinguish development-time data flows from application data flows.
  • Identify evidence needed before sharing confidential data.
  • Use fictional data without concealing important test conditions.

Separate two data flows

Vibe coding is useful for exploring a workflow with fictional records. The risk changes when real company information enters the tool. This can happen before the application has any users.

There are two flows to inspect. The development flow includes prompts, repository context, attachments, tool output, and diagnostic logs. The application flow includes user requests, databases, integrations, telemetry, and backups. Each flow can have different recipients and controls.

Consider a fictional expense application. Its database runs in an approved cloud account. A developer pastes a real claim into an assistant to fix a parser. The claim includes an employee name, a receipt, and bank details. The approved database location does not establish permission for this separate disclosure.

Inspect the complete route

Draw the route before adding confidential data. Name the actual service and account at each step. A product label such as “enterprise” is not a data-flow diagram.

PointQuestion to resolve
Editor or agentWhich files and attachments can it read?
Model serviceWho receives prompts and tool results?
Logs and historyWhat is retained, where, and for how long?
Support accessWho can inspect stored content?
Connected toolsCan retrieved information reach another destination?
Application hostingWhich accounts, regions, and networks hold user data?

Record the applicable contract and configuration. Check subprocessors, deletion behavior, training terms, and international transfers where relevant. Ask the responsible privacy and security owners to resolve uncertainty.

GDPR requirements depend on the processing context. Relevant provisions include data minimization, processor arrangements, security, and impact assessment. Company confidentiality also covers information that is not personal data, such as source code or commercial plans. Read the regulation.

Start with a useful fictional fixture

A safe example still needs realistic structure. Replace names, identifiers, and account numbers. Preserve the conditions that caused the defect: a missing field, an unusual date, or a long description.

Do not label a copied production record “synthetic” after changing one name. Remaining fields can identify a person or disclose a transaction. Build a new record from the schema and the failure condition.

Keep credentials outside prompts and fixtures. If the task needs a secret, use the approved secret mechanism with limited access. An instruction to “keep this private” does not enforce a technical boundary.

Verify, then expand the use

Write a short permitted-use decision: the data categories, approved service configuration, allowed actions, and owner. Include an expiry or review trigger. A new connector, model route, or logging configuration can change the decision.

If information reaches an unapproved recipient, stop further disclosure and follow the incident process. Record what was shared and where. Avoid copying the sensitive material into more tickets or chats.

The practical goal is controlled use. Fictional data supports fast exploration. Verified processing boundaries support the next step into company workflows. Neither a polished demo nor a cloud region answers all the required questions.

Do the exercise

Draw two flows for a fictional expense application: development and production. Include the editor, agent, model provider, logs, database, and support access. Mark unknown recipients. Replace one real expense record with a fictional fixture that preserves the same test conditions.

Download worksheet (Markdown)

Check your understanding

A prototype uses a database in an approved region. Can you paste confidential customer records into its coding assistant?

Sources & further reading

Related reading from Taiga