Client information document

Security Dashboard Data & Privacy Policy

This document explains what can and cannot be inserted into the Systems Studio AI Security Monitor dashboard because of privacy, security, confidentiality and regulatory constraints.

Purpose

Why this document exists

The Systems Studio AI Security Monitor is designed to improve visibility of security events on VPS-hosted portals, client dashboards and technical infrastructure. The dashboard may display operational security information such as IP addresses, timestamps, HTTP status codes, blocked probes and approximate OSINT/IP enrichment.

However, a security dashboard must not become a place where unnecessary personal data, confidential project content, passwords, private keys or sensitive client information are stored or exposed.

IP geolocation is approximate. For cloud/VPS scanners, the displayed location usually points to the hosting provider, ISP or datacenter location, not the exact physical person behind the request.
Allowed data

What can be inserted into the dashboard

The dashboard may show limited operational security information when it is needed to monitor, secure and maintain the client portal.

Allowed security data

  • Source IP address of security-relevant requests
  • Timestamp of the request
  • HTTP method such as GET, POST or HEAD
  • HTTP status code such as 200, 301, 401, 403 or 404
  • Requested URL path, when relevant for security monitoring
  • Fail2Ban jail status and banned IP counters
  • Blocked / redirected / exposed outcome labels
  • Approximate OSINT/IP data: country, city, ISP, organization and ASN
  • Cloud/VPS/hosting classification
  • Telegram alert status and high-level incident summary

Allowed operational notes

  • Security classification such as LOW, MEDIUM or HIGH
  • Dashboard health and last generated timestamp
  • Daily security summary counts
  • Client-area failed access counters
  • Trusted operator IP status, when required
  • General remediation notes such as “blocked by NGINX”
  • Non-sensitive configuration labels
Restricted data

What cannot be inserted into the dashboard

The following data must not be displayed or stored in the security dashboard unless there is a separate, explicit, legally reviewed and client-approved reason to do so.

Never insert secrets or credentials

  • Passwords
  • SSH private keys
  • API keys or API secrets
  • OAuth tokens, JWT tokens or session cookies
  • Database passwords or connection strings
  • Full Authorization headers
  • Backup files, database dumps or configuration files

Never insert unnecessary personal data

  • Full names of visitors or employees unless strictly required
  • Email addresses from visitors or unrelated users
  • Telephone numbers from logs or forms unless required for support
  • Exact physical addresses or GPS traces of persons
  • Private client messages
  • Employee monitoring notes unrelated to security
  • Special-category personal data such as health, religion, political views or union data
The dashboard must never be used as a storage location for client project files, confidential architectural drawings, BIM exports, legal files, financial files, passwords, private keys or personal dossiers.
Redaction rules

Data minimization and redaction

The security monitor follows a data-minimization approach: only the information needed to understand and respond to security events should be shown.

Client responsibility

Client responsibilities

The client remains responsible for deciding which systems, portals and paths may be monitored. Systems Studio can advise on technical setup, but the client should ensure that the monitoring configuration matches their own privacy policy, employment rules, client agreements and legal obligations.

Important limitation

Not a legal opinion

This document is a practical technical and operational policy for the Systems Studio AI Security Monitor. It is not a legal opinion and does not replace legal advice. For GDPR, employment monitoring, regulated industries or sensitive client data, the client should consult a qualified legal or data-protection advisor.