Robots.txt is not access control
Compliant crawlers may avoid disallowed paths, but the URLs remain publicly accessible and can still appear in search results without content. Protect sensitive resources with authentication and use page-level noindex where appropriate.