Security & Data

A fact ledger for company and contact data, credentials, and review controls

This page translates the SUS-E structural slots into an operational security record. It does not claim certification or compliance; it identifies what buyers should verify in their exact agent, provider, and destination configuration.

Data behavior table

AreaExpected controlStatusBuyer verification
Source provenanceRecord provider or public source per consequential fieldConfig-dependentInspect sample output and connector setup
Refresh cadencePreserve checked time and recheck before useProvider-dependentReview current provider documentation
API keysRuntime secret store with least privilegeOperator-controlledInspect scope, logs, rotation, and revocation
Local executionReview package actions, network calls, and filesNot asserted hereTest in an isolated environment
ExportsApproved destinations with access controlsConfig-dependentTrace file, CRM, and engagement-tool copies
DeletionRemove downstream copies as well as package dataOperator-controlledExercise deletion and document exceptions
Human reviewApproval before outreach or bulk exportWorkflow requirementTest role and permission boundaries

“Not asserted here” means current first-party evidence is required. It is not a negative security score.

Evidence checklist

Security and privacy are shared operational responsibilities. An installer cannot determine the purpose of processing, the region of every recipient, or the policies of every destination. Teams should run a data-flow review before production access and repeat it when sources, permissions, regions, or outputs change.

Inspect the command in a controlled environment

npx -y @okki-global/okki-go-taroball