PII, secrets, model usage policy, and the questions your security team will ask.
Where to redact, where to vault, where to refuse the prompt entirely.
The boring controls that make security teams say yes.
A security review pack for your system: data flow diagram, model-usage doc, threat model.