Trust and data

Know where data goes and who approves action.

Yefosec separates public learning, named external checks, advisory evidence and self-hosted solutions. Each surface has a clear data boundary and consequential decisions stay with accountable people.

Data boundaries

Different experiences, different handling.

Use the row that matches the part of Yefosec you are using. Product pages also state their specific boundary beside the main action.

SurfaceDataWhere it goesControl
Public pagesRequested page and basic request/device metadata for cookieless aggregate visitsYefosec hosting and Plausible analyticsTool inputs, lab answers and artifact contents are not included in analytics
Browser-local tools and labsInputs held in page memory or documented local storageYour browser or deviceNo Yefosec scan or lab backend
Source-labelled external checksMinimum query needed by the selected providerThe provider named beside the toolThe boundary is shown before and beside each applicable tool
Self-hosted solutionsOrganisation evidence, integrations and model credentialsThe customer-controlled deployment environmentNot exposed through the public Yefosec site
Advisory engagementWritten scope and agreed evidenceAgreed delivery channels and accountable ownersHandling terms are confirmed in the proposal
Autonomy

A role prompt never grants authority.

Runtime scope, tool access, approval and accountability remain separate from specialist guidance.

A0

ExplainAnswer, teach and propose methods without retrieving private evidence or using live tools.

A1

ObserveRead authorised evidence, analyse it and draft recommendations without changing systems or external state.

A2

PreparePrepare a reversible change or action plan, but do not execute it.

A3

Act with approvalExecute one specifically approved, bounded and reversible action with audit and rollback.

Approval path

Consequential work stays reviewable.

Automation should make the approved path easier to follow, not remove the decision owner.

  1. 01

    Propose: State the evidence, intended effect and confidence.

  2. 02

    Check policy: Confirm scope, authority, impact and prohibited actions.

  3. 03

    Approve: A named human accepts, changes or rejects the proposal.

  4. 04

    Execute and roll back: Only a controlled runtime may perform an authorised reversible action.

  5. 05

    Audit: Retain inputs, decision, result and follow-up owner.

Commitments

Plain controls you can verify.

The public tools, labs and example artifacts let you inspect how these boundaries are expressed before discussing an engagement.

  • Public learning pages do not host a customer SOC, CISO platform or private report store.
  • Every external lookup identifies the provider and the minimum data that leaves the browser.
  • Agent prompts describe specialist judgement; they do not grant tools, credentials or authority.
  • Consequential actions require explicit scope, policy controls, approval and a rollback path.
  • Advisory data handling, access and delivery ownership are agreed in writing before work starts.