Security & Data
This page translates the SUS-E structural slots into an operational security record. It does not claim certification or compliance; it identifies what buyers should verify in their exact agent, provider, and destination configuration.
| Area | Expected control | Status | Buyer verification |
|---|---|---|---|
| Source provenance | Record provider or public source per consequential field | Config-dependent | Inspect sample output and connector setup |
| Refresh cadence | Preserve checked time and recheck before use | Provider-dependent | Review current provider documentation |
| API keys | Runtime secret store with least privilege | Operator-controlled | Inspect scope, logs, rotation, and revocation |
| Local execution | Review package actions, network calls, and files | Not asserted here | Test in an isolated environment |
| Exports | Approved destinations with access controls | Config-dependent | Trace file, CRM, and engagement-tool copies |
| Deletion | Remove downstream copies as well as package data | Operator-controlled | Exercise deletion and document exceptions |
| Human review | Approval before outreach or bulk export | Workflow requirement | Test role and permission boundaries |
“Not asserted here” means current first-party evidence is required. It is not a negative security score.
Security and privacy are shared operational responsibilities. An installer cannot determine the purpose of processing, the region of every recipient, or the policies of every destination. Teams should run a data-flow review before production access and repeat it when sources, permissions, regions, or outputs change.
npx -y @okki-global/okki-go-taroball