Skip to main content

Data Handling

Compliance OS is designed to support cybersecurity and compliance workflows while limiting client-facing applications to the information needed for their purpose.

Types of information

Depending on the engagement, Compliance OS may handle:
  • account and authorization information,
  • interview responses,
  • published assessment information,
  • findings and recommendations,
  • treatments and client actions,
  • evidence and evidence requests,
  • client-facing documents and plans,
  • activity and audit information,
  • governance decisions,
  • application metrics and status information.

Client-safe publication

Cyber Op Source’s internal assessment work may contain draft analysis, reviewer notes, technical workpapers, or material not intended for direct client consumption. Client applications are designed around governed publication or client-safe projections rather than unrestricted internal collection access.

Data minimization

Users should provide information that is relevant to the engagement and avoid unnecessary sensitive data. For example, if a screenshot demonstrates a configuration, redact unrelated personal information, secrets, or identifiers when doing so does not reduce the evidentiary value.

Evidence handling

Evidence can contain sensitive security information. Treat evidence uploads as controlled engagement material. Do not use the evidence workflow to store:
  • passwords,
  • private keys,
  • API secrets,
  • recovery codes,
  • unrelated confidential archives.

Retention and contractual controls

Specific retention, deletion, residency, and service-provider obligations may depend on the applicable agreement, statement of work, client requirements, and configured services. This documentation describes product behavior at a high level and does not replace those governing terms.

Client responsibilities

Clients remain responsible for choosing what information they submit and for ensuring their personnel have authority to provide it. Cyber Op Source remains responsible for operating its portion of the platform and engagement processes in accordance with applicable commitments.