Posting this here because I can't seem to find any answers anywhere. If I use a shapefile at the desktop level that contains sensitive data and publish it as a VTPK to our AGO and then make it public so that it's visibile in a web app, can someone extract the source data from it? Esri says that the VTPK is a vector representation of the data, but that doesn't answer: "Where does the data go?", "Can someone with some know-how hack the VTPK to get at the data?".
I have not seen anything that tells me that someone can not extract the data nor are they able to extract it. Just want to know whether the data is published with it or not.