TekCapitol
Continuous Action Assurance™ · Trust

Data & Confidentiality

Product data posture for enterprise buyers · TekCapitol, Inc.

What TekCapitol needs for Check Write™

By default, Check Write™ is designed around the minimum necessary information to decide Allow / Pause / Block for one consequential action:

· Write Intent / action context (what would change, where, under whose authority)
· Control and evidence references your policy requires for that action
· Schema, metadata, identifiers, freshness stamps, and approval/state signals as configured
· Trace™ decision metadata (outcome, reason codes, provenance labels)

What TekCapitol does not need by default

· Broad extraction of your systems of record
· Full data-warehouse copies
· Unrestricted production data access
· Destination write credentials for TekCapitol to execute customer writes (TekCapitol does not own the write)

Important: We do not claim “no raw data ever.” When a LIVE connector is configured for Assurance Lab or a customer deployment, a query may return field values or state needed for that evidence check. Scope is customer-controlled and should be least privilege.

Data minimization and purpose limitation

Send identifiers, intended changes, authority values, and freshness signals when possible. Prefer hashes or stamps over bulk field dumps. Contracted exceptions (deeper payloads, longer retention, VPC-only processing) are explicit in the engagement or order.

Credentials and secrets

Connector credentials and API secrets are operational configuration. They must not be pasted into public Lab prompts. Trace™ and public demos are not a place for production secrets. Hosted and private deployments use environment-scoped secrets handling appropriate to that deployment.

Trace™

Trace™ records assurance decision evidence: controls evaluated, evidence provenance (including LIVE / SIM / UNAVAILABLE / OFF labels where shown), reasons, and timestamps as configured. Trace™ is for accountability of the decision, not a dump of your full system of record.

Hosted Assurance Lab vs private production

Public / hosted Assurance Lab

May use synthetic demo records and demo-condition injections. Some evidence sources may be LIVE when configured. Workflow text you enter may be stored for the Lab session and may be interpreted by rules and/or an AI model where enabled. Do not submit secrets or sensitive production data into the public demo.

Private / VPC production

Evaluate in SaaS when appropriate. Enforce inside your trust boundary when required. Same decision logic; different deployment boundary. Retention and logging follow the deployment contract.

Confidentiality

Customer architecture details, control inventories, proprietary policies, and pilot materials shared with TekCapitol for evaluation are treated as confidential business information and used only to deliver the requested services. Enterprise engagements may require NDA and DPA before day one. Contact info@tekcapitol.com.

AI / model handling

See AI / Model Data Use for where models may be used, how hosted Lab interpretation works, and how private deployments differ. TekCapitol’s product intent is not to use customer content to train TekCapitol foundation models. Third-party provider terms apply to any external model processing and should be reviewed for your engagement.

Retention and deletion

Website and account personal data retention is described in the Privacy Policy. Product Trace™ and engagement artifacts follow the deployment mode and contract. To request deletion of personal data, email info@tekcapitol.com with subject “Privacy Request”.

Related pages

Security · Privacy · Terms · Technical security docs