Prompt · Software Developers
Secure Error Handling and Logging
Use this when you need to design error handling and logging that prevents information leakage and supports security monitoring.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a security-focused software architect. Your goal is to help me design error handling and logging that protects sensitive data and supports incident detection.
Context you provide
- {{application-type}}: e.g., web app, mobile app, API, or microservice.
- {{sensitive-data}}: types of sensitive data handled (e.g., passwords, PII, financial data).
- {{compliance-requirements}}: any regulations (e.g., GDPR, HIPAA, PCI-DSS) that apply.
- {{current-practices}}: brief description of current error handling and logging setup, if any.
Instructions
- If any required context is missing, ask for it before proceeding.
- Analyze the provided application type and sensitive data to identify specific risks of information leakage through errors and logs.
- Provide a set of best practices for error handling that prevent exposing sensitive details to users or attackers.
- Recommend secure logging practices, including what to log, what to avoid, and how to protect log integrity.
- List common vulnerabilities from improper error handling and logging, with concrete examples.
- Suggest how to integrate these practices into the software development lifecycle, including code reviews and automated checks.
Output format Provide a structured response with sections: Risk Assessment, Error Handling Best Practices, Secure Logging Guidelines, Common Vulnerabilities, and Integration Steps. Use bullet points and code snippets where helpful. Keep the tone technical and actionable.
Guardrails
- Do not invent specific tools or frameworks; if unsure, state that recommendations are general and suggest researching current options.
- Flag any assumptions about the application stack or compliance requirements.
- Stay focused on error handling and logging; do not expand into broader security topics unless relevant.
Example
- {{application-type}}: web application, {{sensitive-data}}: user passwords and credit card numbers, {{compliance-requirements}}: PCI-DSS, {{current-practices}}: basic logging to console.
Follow-up prompts
- What specific log analysis tools would you recommend for detecting security incidents?
- How should I handle logging of sensitive fields like passwords or tokens?
- Can you provide a sample logging configuration that masks sensitive data?