data-exposure
Safeguard articles tagged "data-exposure" — guides, analysis, and best practices for software supply chain and application security.
9 articles
Your Feature Flag Targeting Rules Are Visible in the Browser
To evaluate flags locally, the client-side SDK needs the targeting rules: which accounts get the enterprise preview, the pricing tier conditions, the churn-risk exclusions. Open the network panel and anyone can read all of it.
Your API Returns More Than Your Interface Shows
The interface filters. The API does not. Serialising a model directly makes your API contract your database schema, so a column added for an internal feature is exposed the moment it is added.
Your Search Index Is a Second Database With None of Your Access Controls
A missing clause in a database query returns too much. A missing clause in a search query returns everything, across every customer, ranked by relevance.
When the Cache Key Leaks One User's Page to Another
A personalised response cached under a key that does not include the thing that made it personal. One of the few bugs that discloses one customer's data to another with no attacker involved, and it arrives as a confused support ticket.
When NULL Tenant Means Global, Forgetting the Tenant Means Disclosure
A nullable tenant_id where NULL means global makes omission the unsafe state, and SQL NULL semantics mean the mistake never raises an error. The admin view looks full and correct while tenant-scoped rows are simply absent.
Security considerations for deploying and querying vector...
Vector databases now hold copies of your most sensitive data with weaker controls than the systems they came from. Here's what to fix before your next RAG deployment.
S3 bucket misconfiguration vulnerabilities explained
S3 misconfigurations have exposed hundreds of millions of records in breaches from Deep Root Analytics to Capital One. Here's how they happen and how to catch them.
Was ServiceNow Hacked? What the Data Exposure Incidents Actually Mean
The phrase 'ServiceNow hacked' usually points to misconfiguration and unauthenticated API access, not a core platform breach. Here is what happened and how to protect your instance.
DeepSeek ClickHouse Exposure: When the AI Vendor Forgets the Database
In January 2025 Wiz Research found a wide-open ClickHouse instance belonging to AI startup DeepSeek, leaking chat history, API keys, and internal log streams. We unpack the AI-supply-chain implications.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.