It sounds like you have includeExceptionDetailInFaults="true". True is the default value that should be set to false before you do a production deploy. Once this is false you will get a generic error message. That should be enough to make security happy.
An even better option is to implement an IErrorHandler. That's the extension point that allow you to handle the exception, even though it happens before execution reaches your service code.