What is RAG security?
RAG security is the discipline of protecting retrieval-augmented generation systems across source data, indexing, retrieval, context assembly, model response, citations, logs, and downstream actions.
How does RAG data leakage happen?
RAG data leakage can happen when retrieval returns content outside a user's authorization, when summaries expose sensitive fragments, when citations reveal restricted sources, or when logs and memory preserve data that should not persist.
What is RAG prompt injection?
RAG prompt injection occurs when retrieved content contains instructions that try to alter the model's behavior, override policy, misuse tools, or change how the agent responds to the user.
How should RAG security testing be done?
Testing should combine authorization checks, adversarial documents, poisoned retrieval cases, sensitive data probes, citation review, log inspection, and end-to-end validation of how retrieved context affects tools or decisions.
Should retrieved content be treated as instructions?
No. Retrieved content should be treated as untrusted data unless the system has strong controls that separate source material from developer policy, authorization decisions, and tool execution rules.
How does Orbyntis evaluate RAG security?
Orbyntis evaluates RAG security by mapping data sources, access rules, retrieval behavior, prompt injection paths, leakage channels, citation integrity, evidence retention, and operational ownership.