Overview
This document follows information from an authorized customer source through retrieval, model inference, output and audit logging. It is designed to help security and privacy reviewers identify trust boundaries and control owners.
Actual systems, regions, providers, retention and integrations are confirmed in the deployment record.
Primary flow
- Authorized operational systems expose signals through customer-approved integrations.
- OpsRabbit retrieves only information permitted by configured identities and scopes.
- The product assembles relevant evidence and trusted instructions.
- Required context is sent to the customer-approved model endpoint for inference.
- OpsRabbit presents evidence-backed analysis and records relevant audit events.
- Any authorized action follows applicable permission and approval controls.
Data categories
- Operational alerts, logs, metrics, tickets and service context
- User, role and approval metadata
- Model context, output and supporting evidence
- Tool-call, policy-decision, error and security events
Boundary controls
Customer operational data remains in the approved customer-hosted and provider boundaries. Egress, storage, retention, support access and backups depend on the agreed architecture. Secrets should be supplied through managed connections and excluded from model context.
Data inventory
| Stage | Typical data | Primary control |
|---|---|---|
| Source access | Alerts, metrics, logs, traces, tickets, topology and service metadata | Customer-approved identity and scope |
| Retrieval and correlation | Task-relevant evidence and relationships | Minimization, authorization and isolation |
| Model context | Selected evidence, instructions and task metadata | Trusted-instruction separation, secret exclusion and approved endpoint |
| Output | Analysis, evidence citations and recommendations | Human validation and action controls |
| Audit | Actor, tool, model, policy, approval and result metadata | Restricted access, integrity and configured retention |
Support and administrative access
OpsRabbit provider personnel do not receive standing access to customer operational data solely because OpsRabbit is deployed. Any support access must be authorized, time-bounded, least-privilege and logged. The customer should remove access at the end of the activity. Customer data should not be transferred into general support channels where a secure alternative is available.
Cross-border and provider flows
The deployment record identifies where OpsRabbit components, customer data and model inference operate. Customer-selected providers may create separate cross-border transfers and retention obligations. OpsRabbit provider does not change the approved provider or processing location without the governance and notice required by the agreement.
Deployment exit
At the end of the service or evaluation, the parties disable temporary accounts and integrations, revoke credentials, return or delete OpsRabbit provider-controlled customer data, preserve only required security or contractual evidence, and confirm responsibility for customer-hosted databases, logs and backups.