Security Dashboard Data & Privacy Policy
This document explains what can and cannot be inserted into the Systems Studio AI Security Monitor dashboard because of privacy, security, confidentiality and regulatory constraints.
Why this document exists
The Systems Studio AI Security Monitor is designed to improve visibility of security events on VPS-hosted portals, client dashboards and technical infrastructure. The dashboard may display operational security information such as IP addresses, timestamps, HTTP status codes, blocked probes and approximate OSINT/IP enrichment.
However, a security dashboard must not become a place where unnecessary personal data, confidential project content, passwords, private keys or sensitive client information are stored or exposed.
What can be inserted into the dashboard
The dashboard may show limited operational security information when it is needed to monitor, secure and maintain the client portal.
Allowed security data
- Source IP address of security-relevant requests
- Timestamp of the request
- HTTP method such as GET, POST or HEAD
- HTTP status code such as 200, 301, 401, 403 or 404
- Requested URL path, when relevant for security monitoring
- Fail2Ban jail status and banned IP counters
- Blocked / redirected / exposed outcome labels
- Approximate OSINT/IP data: country, city, ISP, organization and ASN
- Cloud/VPS/hosting classification
- Telegram alert status and high-level incident summary
Allowed operational notes
- Security classification such as LOW, MEDIUM or HIGH
- Dashboard health and last generated timestamp
- Daily security summary counts
- Client-area failed access counters
- Trusted operator IP status, when required
- General remediation notes such as “blocked by NGINX”
- Non-sensitive configuration labels
What cannot be inserted into the dashboard
The following data must not be displayed or stored in the security dashboard unless there is a separate, explicit, legally reviewed and client-approved reason to do so.
Never insert secrets or credentials
- Passwords
- SSH private keys
- API keys or API secrets
- OAuth tokens, JWT tokens or session cookies
- Database passwords or connection strings
- Full Authorization headers
- Backup files, database dumps or configuration files
Never insert unnecessary personal data
- Full names of visitors or employees unless strictly required
- Email addresses from visitors or unrelated users
- Telephone numbers from logs or forms unless required for support
- Exact physical addresses or GPS traces of persons
- Private client messages
- Employee monitoring notes unrelated to security
- Special-category personal data such as health, religion, political views or union data
Data minimization and redaction
The security monitor follows a data-minimization approach: only the information needed to understand and respond to security events should be shown.
- Query strings should be hidden or shortened when they may contain tokens, email addresses or personal data.
- Long user-agent strings may be shortened when not needed for analysis.
- Request bodies should not be displayed in the dashboard.
- Authentication headers and cookies must not be displayed.
- Client names, project names and internal paths should be generalized when possible.
- Trusted operator IPs may be whitelisted so they do not generate unnecessary alert noise.
Client responsibilities
The client remains responsible for deciding which systems, portals and paths may be monitored. Systems Studio can advise on technical setup, but the client should ensure that the monitoring configuration matches their own privacy policy, employment rules, client agreements and legal obligations.
- The client should identify which portal paths contain NDA-sensitive files.
- The client should confirm who may access the security dashboard.
- The client should avoid sending passwords or private keys through email or web forms.
- The client should inform Systems Studio if internal policies prohibit remote access or require on-site work.
- The client should request legal review when the dashboard is used in a regulated environment.
Not a legal opinion
This document is a practical technical and operational policy for the Systems Studio AI Security Monitor. It is not a legal opinion and does not replace legal advice. For GDPR, employment monitoring, regulated industries or sensitive client data, the client should consult a qualified legal or data-protection advisor.