Can users see my system prompt?
Assume yes. Determined users can usually get a model to reveal its instructions, in full or in paraphrase, and no prompt wording reliably prevents it. System prompt leakage is LLM07 in the OWASP Top 10 for LLM applications. The fix is not a better secrecy instruction but a prompt that contains nothing harmful if published: no keys, no internal URLs, no other customers' data and no access rules the app depends on.
Never put these in a prompt
- API keys, tokens or passwords.
- Internal hostnames, database names or admin URLs.
- Other users' or customers' data.
- Pricing or discount rules you do not want public.
- Access control decisions, such as "only answer admins about billing". Enforce those in code.
What is fine
Tone, format, the product's purpose, public facts and refusal guidance. If a competitor copied it, you would lose little.
Check yours
Ask your own feature to repeat its instructions, translate them, or summarise the rules it follows. If anything sensitive appears, move it into code.
Designing as if it is public
Move every rule that matters out of the prompt and into code. If only paying users may ask about a premium topic, check the plan before calling the model, not in the instructions. If the assistant may only discuss the user's own account, retrieve only that account's data; do not ask the model to ignore the rest. If certain words or actions are forbidden, filter the output in code as well.
The prompt then becomes guidance on tone and task, which is harmless to publish. Some teams publish their prompts deliberately, which removes the incentive to extract them. Either way, review the prompt for anything sensitive before each release, since prompts change often and are rarely reviewed like code.
Getting it checked
TrazTech offers AI and LLM security assessments, listed from $4,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.
Related questions
Get a scope for your app
Tell us what you built, what it stores and who is about to use it.
Get matchedCommon questions
Is my prompt intellectual property?
It may be valuable, but treat it as public. The value of your product should not depend on a prompt staying secret.
Do output filters stop leakage?
They catch exact copies. Paraphrased or translated leaks usually get through.