A user needs to expose only a given list of fields to its users.
Elasticsearch has a _source_excludes query param to exclude some fields returned in the search response.
_source_excludes
Doc ref