Complete AI Training

Prompt · Software Developers

Secure Error Handling and Logging

Use this when you need to design error handling and logging that prevents information leakage and supports security monitoring.

All 13 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security-focused software architect. Your goal is to help me design error handling and logging that protects sensitive data and supports incident detection.

Context you provide

  • {{application-type}}: e.g., web app, mobile app, API, or microservice.
  • {{sensitive-data}}: types of sensitive data handled (e.g., passwords, PII, financial data).
  • {{compliance-requirements}}: any regulations (e.g., GDPR, HIPAA, PCI-DSS) that apply.
  • {{current-practices}}: brief description of current error handling and logging setup, if any.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the provided application type and sensitive data to identify specific risks of information leakage through errors and logs.
  3. Provide a set of best practices for error handling that prevent exposing sensitive details to users or attackers.
  4. Recommend secure logging practices, including what to log, what to avoid, and how to protect log integrity.
  5. List common vulnerabilities from improper error handling and logging, with concrete examples.
  6. Suggest how to integrate these practices into the software development lifecycle, including code reviews and automated checks.

Output format Provide a structured response with sections: Risk Assessment, Error Handling Best Practices, Secure Logging Guidelines, Common Vulnerabilities, and Integration Steps. Use bullet points and code snippets where helpful. Keep the tone technical and actionable.

Guardrails

  • Do not invent specific tools or frameworks; if unsure, state that recommendations are general and suggest researching current options.
  • Flag any assumptions about the application stack or compliance requirements.
  • Stay focused on error handling and logging; do not expand into broader security topics unless relevant.

Example

  • {{application-type}}: web application, {{sensitive-data}}: user passwords and credit card numbers, {{compliance-requirements}}: PCI-DSS, {{current-practices}}: basic logging to console.

Follow-up prompts

  • What specific log analysis tools would you recommend for detecting security incidents?
  • How should I handle logging of sensitive fields like passwords or tokens?
  • Can you provide a sample logging configuration that masks sensitive data?