DocumentationSecurity review

Data protection and privacy review

Map the data each integration processes and the privacy evidence needed before a rollout.

Updated 2026-09-22 Read as Markdown
On this page

Build a data map for your integration

Kastra evaluates the context needed to apply an action policy. The data involved depends on the integration and enabled features. Start with synthetic content and review the collection scope before using production repositories, prompts, or tool arguments.

Data pathWhat is processedReview decision
Edge evaluationSupported tool input, target paths, action attributes, and available prompt context sent to KastraWhich repositories and action fields may enter the service?
ProxySupported provider request and response content; upstream credential used for forwardingWhich models, data classes, provider accounts, and output paths are approved?
Local MCPTool names, catalog context, and call arguments used for evaluationWhich servers and sensitive arguments may be connected?
ReconSupported local history, redacted on the device before candidate summaries are uploaded for analysisWhich devices and history sources may participate in scanning?
Policy assistanceRule descriptions and supported examples/context used by configured model servicesWhat may be included in a draft or suggested correction?
Usage reportingSupported client-reported usage events, separate from proxy meteringWhich telemetry is enabled and who reviews its collection?

Understand masking, storage, and forwarding

Stored-payload masking, encrypted-original storage, and forwarded-content redaction are separate controls. A masked decision can coexist with an encrypted original under the configured storage policy. A redacted outbound request changes what reaches the provider on that path.

Test these controls with synthetic sensitive values. Inspect the recorded view, exported material, and downstream payload where you control the receiver. Detector scope and payload limits determine what is inspected. Technical data-handling guide.

Prepare the GDPR review

Use the Kastra Trust Center as the starting point for GDPR documentation and privacy due diligence. Identify the parties’ roles for your use case, processing purposes, data categories, and instructions. Review the applicable data processing agreement and technical and organizational measures with your privacy team.

The European Commission’s data-protection obligations guidance covers transparency, safeguards and ongoing review. Have your privacy team assess the processing relationship and applicable terms for your deployment.

Confirm the deployment-specific terms

Record the agreed processing locations, relevant subprocessors and analysis providers, access controls, retention and deletion schedules, support access, and handling of data-subject or incident requests. For international transfers, have your privacy team review the applicable mechanism and contract for the actual parties and locations.

A policy’s jurisdiction attribute supplies evaluation context; it does not select a hosting region. Confirm residency in the deployment and contractual documentation. If a document is unavailable in the portal, request it from Kastra and record the open question before approving the affected data use.

Keep the review current

Revisit the data map when enabling another integration, Recon scanning, policy assistance, telemetry, or a different provider. Name an owner for retention and deletion verification. The assurance guide explains how vendor evidence and your implementation review fit together.