Skip to main content
Detection inputs and findings can themselves contain sensitive information. Apply the same data-handling discipline to the analysis path that you apply to the source system.

Minimize exposure

  • Send only the content required for the analysis.
  • Avoid copying raw content into logs, traces, support tickets, or metrics.
  • Restrict access to inputs, findings, and retained evidence by purpose.
  • Define retention and deletion behavior before enabling durable storage.
  • Use synthetic or redacted examples for development whenever they preserve the behavior under test.

Preserve text integrity

When a result identifies a span, retain the declared encoding, normalization, and offset unit alongside the source text. Transforming text after analysis can invalidate offsets and cause a finding to point at the wrong bytes.

Treat failures explicitly

Design callers for timeouts, unavailable producers, unsupported media, rejected inputs, and partial results. A secure integration fails visibly; it does not silently treat an incomplete analysis as clean content.
Never include credentials, customer data, or production-sensitive payloads in documentation examples or issue reports.