It could be added to context only on the inference server, with the model heavily instructed not to repeat its contents. Not foolproof, obviously.