Trust and data

Know where data goes and who approves action.

Yefosec separates public learning, named external checks, advisory evidence and self-hosted solutions. Each surface has a clear data boundary and consequential decisions stay with accountable people.

Data boundaries

Different experiences, different handling.

Use the row that matches the part of Yefosec you are using. Product pages also state their specific boundary beside the main action.

SurfaceDataWhere it goesControl
Public pagesRequested page and basic request/device metadata for cookieless aggregate visitsYefosec hosting and Plausible analyticsTool inputs, lab answers and artifact contents are not included in analytics
Browser-local tools and labsInputs held in page memory or documented local storageYour browser or deviceNo Yefosec scan or lab backend
Source-labelled external checksMinimum query needed by the selected providerThe provider named beside the toolThe boundary is shown before and beside each applicable tool
Self-hosted solutionsOrganisation evidence, integrations and model credentialsThe customer-controlled deployment environmentNot exposed through the public Yefosec site
Advisory engagementWritten scope and agreed evidenceAgreed delivery channels and accountable ownersHandling terms are confirmed in the proposal

Model placement

Choose the boundary before choosing the model.

The self-hosted runtime supports explicit egress modes at the tool-policy layer. Available providers and retention terms still depend on the customer deployment.

Local / no egress

Browser or customer environment

Deterministic tools, fixed workflow logic and models hosted entirely inside the deployment boundary.

External model and tool egress are denied by policy.

Hosted / pseudonymised

Approved hosted inference endpoint

Only the fields needed for the approved task are sent after configured redaction and pseudonymisation.

The operator sees the field manifest before approval; the investigation ledger retains a digest, not the raw response.

Customer-managed / BYOK

Customer-selected endpoint and credentials

The organisation selects the model provider, exact model route, network path, key source and retention terms. Agents use logical aliases through a normalized gateway, so hosted and local routes can be replaced without changing authority.

Secret references remain separate from prompts, logs and exported case dossiers.

Egress preview

What an approved hosted call can expose.

This is the declared field shape, not a live request. A production call still requires the matching role, policy, scope and case budget.

Included
Alert type, evidence summaries, asset criticality, requested decision
Pseudonymised
Email addresses, IP addresses, host and identity labels
Excluded
Credentials, tokens, raw payloads, file content and unrelated case history
Ledger record
Provider mode, field names, redacted byte count, policy version and output digest
Autonomy

A role prompt never grants authority.

Runtime scope, tool access, approval and accountability remain separate from specialist guidance.

A0

ExplainAnswer, teach and propose methods without retrieving private evidence or using live tools.

A1

ObserveRead authorised evidence, analyse it and draft recommendations without changing systems or external state.

A2

PreparePrepare a reversible change or action plan, but do not execute it.

A3

Act with approvalExecute one specifically approved, bounded and reversible action with audit and rollback.

Independent action risk

Autonomy says who may act; risk says what the action can do. Both gates must pass.

R0

SimulationNo external state or customer data is changed.

R1

Read onlyAuthorised evidence may be retrieved without changing the source.

R2

ReversibleA bounded change requires exact approval, verification and rollback.

R3

MaterialA higher-impact reversible action requires tighter scope and supervision.

R4

DestructiveThe agentic runtime refuses destructive or irreversible execution.

Approval path

Consequential work stays reviewable.

Automation should make the approved path easier to follow, not remove the decision owner. Approval is bound to the exact action, targets, parameters, policy version and expiry.

  1. 01

    Propose: State the evidence, intended effect and confidence.

  2. 02

    Check policy: Confirm scope, authority, impact and prohibited actions.

  3. 03

    Approve: A named human accepts, changes or rejects the proposal.

  4. 04

    Execute and roll back: Only a controlled runtime may perform an authorised reversible action.

  5. 05

    Audit: Retain inputs, decision, result and follow-up owner.

Connector lifecycle

A contract is not a live integration.

Yefosec publishes provider-neutral capability boundaries before any customer connection exists. Status advances only when the next evidence gate is satisfied.

  1. 01

    Contract defined

    Logical capability, authentication type, data class and write boundary are versioned.

  2. 02

    Fixture validated

    A provider adapter passes normalization, tenancy, failure and provenance fixtures.

  3. 03

    Customer qualified

    The adapter is tested against the customer identity, policy, rate limits and source schema.

  4. 04

    Production accepted

    Named owners accept monitoring, recovery, residual risk and operational support.

Connector contractCapabilitiesData classesCurrent status
Microsoft Entra IDidentity.directory.read, identity.signin.read, identity.entitlement.read, identity.session.revokeidentity, auditContract defined
Oktaidentity.directory.read, identity.signin.read, identity.session.revokeidentity, auditContract defined
PAM Adapterpam.audit.read, identity.entitlement.readrestricted, identityContract defined
AWS Securitycloud.asset.read, cloud.audit.read, cloud.finding.read, kms.inventory.readcloud-metadata, security-findingsContract defined
Azure Securitycloud.asset.read, cloud.audit.read, cloud.finding.read, kms.inventory.readcloud-metadata, security-findingsContract defined
Google Cloud Securitycloud.asset.read, cloud.audit.read, cloud.finding.read, kms.inventory.readcloud-metadata, security-findingsContract defined
Kubernetesk8s.config.read, cloud.asset.readconfiguration, workloadsContract defined
Application Security Scanner Adaptersast.finding.read, dast.finding.read, iac.scan, mobile.app.scan, api.inventory.readsource-metadata, findingsContract defined
Source Control Adapterscm.read, artifact.provenance.readsource-metadata, build-metadataContract defined
Data Security Adapterdata.catalog.read, dlp.finding.read, crypto.inventory.read, certificate.inventory.read, crypto.testrestricted-metadata, findingsContract defined
Vulnerability Platform Adapterasset.inventory.read, vulnerability.finding.read, remediation.verifyassets, findingsContract defined
ITSM and Case Adapterticket.write, privacy.case.write, insider.case.write, audit.case.write, maintenance.ticket.writecases, approvalsContract defined
Forensic Tool Adapterendpoint.acquire, forensic.store.write, timeline.analyse, yara.scanrestricted, evidenceContract defined
Malware Sandbox Adaptermalware.sandbox.submitmalware, restrictedContract defined
OT Monitoring Adapterot.asset.read, ot.network.passive_read, ot.alert.read, safety.context.readindustrial, safetyContract defined
Human Risk Adapterlearning.metrics.read, phishing.simulation.read, ueba.alert.read, hr.case_reference.readpersonal, restrictedContract defined
Backup and Recovery Adapterbackup.inventory.read, backup.restore.executebackup-metadata, recoveryContract defined
Mobile Device Management Adaptermdm.device.read, mobile.threat.read, mobile.device.actiondevice, identityContract defined
STIX/TAXII Threat Intelligence Adapterthreat.feed.read, stix.collection.read, threat.exploitability.readintelligenceContract defined
External Attack Surface Adapterexternal.asset.read, dns.ct.readpublic-observationsContract defined
Governance Evidence Adaptercontrol.evidence.read, policy.read, risk.register.read, service.dependency.read, crisis.exercise.writegovernance, confidentialContract defined

All 21 published entries are contracts. None is represented here as customer-qualified or production accepted.

Commitments

Plain controls you can verify.

The public tools, labs and example artifacts let you inspect how these boundaries are expressed before discussing an engagement.

  • Public learning pages do not host a customer SOC, CISO platform or private report store.
  • Every external lookup identifies the provider and the minimum data that leaves the browser.
  • Agent prompts describe specialist judgement; they do not grant tools, credentials or authority.
  • Every governed tool call is bound to a short-lived workload identity, exact destination and independently enforced run budget.
  • Unexpected external behavior and repeated denied actions suspend the run outside the model.
  • Consequential actions require explicit scope, policy controls, approval and a rollback path.
  • Advisory data handling, access and delivery ownership are agreed in writing before work starts.