Know where data goes and who approves action.
Yefosec separates public learning, named external checks, advisory evidence and self-hosted solutions. Each surface has a clear data boundary and consequential decisions stay with accountable people.
Data boundaries
Different experiences, different handling.
Use the row that matches the part of Yefosec you are using. Product pages also state their specific boundary beside the main action.
| Surface | Data | Where it goes | Control |
|---|---|---|---|
| Public pages | Requested page and basic request/device metadata for cookieless aggregate visits | Yefosec hosting and Plausible analytics | Tool inputs, lab answers and artifact contents are not included in analytics |
| Browser-local tools and labs | Inputs held in page memory or documented local storage | Your browser or device | No Yefosec scan or lab backend |
| Source-labelled external checks | Minimum query needed by the selected provider | The provider named beside the tool | The boundary is shown before and beside each applicable tool |
| Self-hosted solutions | Organisation evidence, integrations and model credentials | The customer-controlled deployment environment | Not exposed through the public Yefosec site |
| Advisory engagement | Written scope and agreed evidence | Agreed delivery channels and accountable owners | Handling terms are confirmed in the proposal |
A role prompt never grants authority.
Runtime scope, tool access, approval and accountability remain separate from specialist guidance.
ExplainAnswer, teach and propose methods without retrieving private evidence or using live tools.
ObserveRead authorised evidence, analyse it and draft recommendations without changing systems or external state.
PreparePrepare a reversible change or action plan, but do not execute it.
Act with approvalExecute one specifically approved, bounded and reversible action with audit and rollback.
Consequential work stays reviewable.
Automation should make the approved path easier to follow, not remove the decision owner.
- 01
Propose: State the evidence, intended effect and confidence.
- 02
Check policy: Confirm scope, authority, impact and prohibited actions.
- 03
Approve: A named human accepts, changes or rejects the proposal.
- 04
Execute and roll back: Only a controlled runtime may perform an authorised reversible action.
- 05
Audit: Retain inputs, decision, result and follow-up owner.
Commitments
Plain controls you can verify.
The public tools, labs and example artifacts let you inspect how these boundaries are expressed before discussing an engagement.
- Public learning pages do not host a customer SOC, CISO platform or private report store.
- Every external lookup identifies the provider and the minimum data that leaves the browser.
- Agent prompts describe specialist judgement; they do not grant tools, credentials or authority.
- Consequential actions require explicit scope, policy controls, approval and a rollback path.
- Advisory data handling, access and delivery ownership are agreed in writing before work starts.