Data Handling
Compliance OS is designed to support cybersecurity and compliance workflows while limiting client-facing applications to the information needed for their purpose.Types of information
Depending on the engagement, Compliance OS may handle:- account and authorization information,
- interview responses,
- published assessment information,
- findings and recommendations,
- treatments and client actions,
- evidence and evidence requests,
- client-facing documents and plans,
- activity and audit information,
- governance decisions,
- application metrics and status information.
Client-safe publication
Cyber Op Source’s internal assessment work may contain draft analysis, reviewer notes, technical workpapers, or material not intended for direct client consumption. Client applications are designed around governed publication or client-safe projections rather than unrestricted internal collection access.Data minimization
Users should provide information that is relevant to the engagement and avoid unnecessary sensitive data. For example, if a screenshot demonstrates a configuration, redact unrelated personal information, secrets, or identifiers when doing so does not reduce the evidentiary value.Evidence handling
Evidence can contain sensitive security information. Treat evidence uploads as controlled engagement material. Do not use the evidence workflow to store:- passwords,
- private keys,
- API secrets,
- recovery codes,
- unrelated confidential archives.