Public Data Rules
The public dashboard, event summaries, reports, and unauthenticated APIs show sanitized aggregate data only.
| Shown publicly | Green data: counts, trends, severity, category, coarse country/network context, and normalized client type. |
| Kept private | Raw IP hashes, request headers, payloads, canary tokens, session IDs, full user agents, customer details, and API keys. |
| Paid defensive feeds | Yellow_1+ IOC feeds may include source IP indicators with confidence, context, TTL, and recommended defensive action. Yellow_2+ payload-intelligence feeds may include payload hashes, command-pattern labels, extracted payload URLs/domains, richer payload context, and related source IPs. Yellow_3 may include full ordered behavior timelines. These feeds exclude raw headers, payload bodies, tokens, credentials, red evidence, and private source IP hashes. |
| Map data | Attack-map locations are approximate and may use country-level or trusted edge-header attribution. |