Slide 2 of 27
Part 1 · What Is It?Slide 2
Slide 2 · The Word
What actually counts as “sensitive information”?
OWASP names six categories. Most teams only think about one.
🪪
Personal Identifiable Information (PII)
Names, emails, phone numbers, addresses — anything that identifies a specific person.
💳
Financial details
Account numbers, transaction histories, payment data.
🏥
Health records
Medical history, diagnoses, treatment information.
🏢
Confidential business data
Trade secrets, strategy documents, internal communications.
🔑
Security credentials
API keys, passwords, tokens, access codes.
⚖️
Legal documents
Contracts, litigation materials, compliance filings.
A Seventh Category, Easy to Forget

Proprietary models add another layer: a model's own training methods and source code can be sensitive too — especially for closed or foundation models. Slide 11 covers exactly this.

← BackNext → The Definition Part 1