Local / no egress
Browser or customer environmentDeterministic tools, fixed workflow logic and models hosted entirely inside the deployment boundary.
External model and tool egress are denied by policy.
Yefosec separates public learning, named external checks, advisory evidence and self-hosted solutions. Each surface has a clear data boundary and consequential decisions stay with accountable people.
Data boundaries
Use the row that matches the part of Yefosec you are using. Product pages also state their specific boundary beside the main action.
| Surface | Data | Where it goes | Control |
|---|---|---|---|
| Public pages | Requested page and basic request/device metadata for cookieless aggregate visits | Yefosec hosting and Plausible analytics | Tool inputs, lab answers and artifact contents are not included in analytics |
| Browser-local tools and labs | Inputs held in page memory or documented local storage | Your browser or device | No Yefosec scan or lab backend |
| Source-labelled external checks | Minimum query needed by the selected provider | The provider named beside the tool | The boundary is shown before and beside each applicable tool |
| Self-hosted solutions | Organisation evidence, integrations and model credentials | The customer-controlled deployment environment | Not exposed through the public Yefosec site |
| Advisory engagement | Written scope and agreed evidence | Agreed delivery channels and accountable owners | Handling terms are confirmed in the proposal |
Model placement
The self-hosted runtime supports explicit egress modes at the tool-policy layer. Available providers and retention terms still depend on the customer deployment.
Deterministic tools, fixed workflow logic and models hosted entirely inside the deployment boundary.
External model and tool egress are denied by policy.
Only the fields needed for the approved task are sent after configured redaction and pseudonymisation.
The operator sees the field manifest before approval; the investigation ledger retains a digest, not the raw response.
The organisation selects the model provider, exact model route, network path, key source and retention terms. Agents use logical aliases through a normalized gateway, so hosted and local routes can be replaced without changing authority.
Secret references remain separate from prompts, logs and exported case dossiers.
This is the declared field shape, not a live request. A production call still requires the matching role, policy, scope and case budget.
Runtime scope, tool access, approval and accountability remain separate from specialist guidance.
ExplainAnswer, teach and propose methods without retrieving private evidence or using live tools.
ObserveRead authorised evidence, analyse it and draft recommendations without changing systems or external state.
PreparePrepare a reversible change or action plan, but do not execute it.
Act with approvalExecute one specifically approved, bounded and reversible action with audit and rollback.
Autonomy says who may act; risk says what the action can do. Both gates must pass.
SimulationNo external state or customer data is changed.
Read onlyAuthorised evidence may be retrieved without changing the source.
ReversibleA bounded change requires exact approval, verification and rollback.
MaterialA higher-impact reversible action requires tighter scope and supervision.
DestructiveThe agentic runtime refuses destructive or irreversible execution.
Automation should make the approved path easier to follow, not remove the decision owner. Approval is bound to the exact action, targets, parameters, policy version and expiry.
Propose: State the evidence, intended effect and confidence.
Check policy: Confirm scope, authority, impact and prohibited actions.
Approve: A named human accepts, changes or rejects the proposal.
Execute and roll back: Only a controlled runtime may perform an authorised reversible action.
Audit: Retain inputs, decision, result and follow-up owner.
Yefosec publishes provider-neutral capability boundaries before any customer connection exists. Status advances only when the next evidence gate is satisfied.
Logical capability, authentication type, data class and write boundary are versioned.
A provider adapter passes normalization, tenancy, failure and provenance fixtures.
The adapter is tested against the customer identity, policy, rate limits and source schema.
Named owners accept monitoring, recovery, residual risk and operational support.
| Connector contract | Capabilities | Data classes | Current status |
|---|---|---|---|
| Microsoft Entra ID | identity.directory.read, identity.signin.read, identity.entitlement.read, identity.session.revoke | identity, audit | Contract defined |
| Okta | identity.directory.read, identity.signin.read, identity.session.revoke | identity, audit | Contract defined |
| PAM Adapter | pam.audit.read, identity.entitlement.read | restricted, identity | Contract defined |
| AWS Security | cloud.asset.read, cloud.audit.read, cloud.finding.read, kms.inventory.read | cloud-metadata, security-findings | Contract defined |
| Azure Security | cloud.asset.read, cloud.audit.read, cloud.finding.read, kms.inventory.read | cloud-metadata, security-findings | Contract defined |
| Google Cloud Security | cloud.asset.read, cloud.audit.read, cloud.finding.read, kms.inventory.read | cloud-metadata, security-findings | Contract defined |
| Kubernetes | k8s.config.read, cloud.asset.read | configuration, workloads | Contract defined |
| Application Security Scanner Adapter | sast.finding.read, dast.finding.read, iac.scan, mobile.app.scan, api.inventory.read | source-metadata, findings | Contract defined |
| Source Control Adapter | scm.read, artifact.provenance.read | source-metadata, build-metadata | Contract defined |
| Data Security Adapter | data.catalog.read, dlp.finding.read, crypto.inventory.read, certificate.inventory.read, crypto.test | restricted-metadata, findings | Contract defined |
| Vulnerability Platform Adapter | asset.inventory.read, vulnerability.finding.read, remediation.verify | assets, findings | Contract defined |
| ITSM and Case Adapter | ticket.write, privacy.case.write, insider.case.write, audit.case.write, maintenance.ticket.write | cases, approvals | Contract defined |
| Forensic Tool Adapter | endpoint.acquire, forensic.store.write, timeline.analyse, yara.scan | restricted, evidence | Contract defined |
| Malware Sandbox Adapter | malware.sandbox.submit | malware, restricted | Contract defined |
| OT Monitoring Adapter | ot.asset.read, ot.network.passive_read, ot.alert.read, safety.context.read | industrial, safety | Contract defined |
| Human Risk Adapter | learning.metrics.read, phishing.simulation.read, ueba.alert.read, hr.case_reference.read | personal, restricted | Contract defined |
| Backup and Recovery Adapter | backup.inventory.read, backup.restore.execute | backup-metadata, recovery | Contract defined |
| Mobile Device Management Adapter | mdm.device.read, mobile.threat.read, mobile.device.action | device, identity | Contract defined |
| STIX/TAXII Threat Intelligence Adapter | threat.feed.read, stix.collection.read, threat.exploitability.read | intelligence | Contract defined |
| External Attack Surface Adapter | external.asset.read, dns.ct.read | public-observations | Contract defined |
| Governance Evidence Adapter | control.evidence.read, policy.read, risk.register.read, service.dependency.read, crisis.exercise.write | governance, confidential | Contract defined |
All 21 published entries are contracts. None is represented here as customer-qualified or production accepted.
Commitments
The public tools, labs and example artifacts let you inspect how these boundaries are expressed before discussing an engagement.