Sensitive Data Classification and Routing
A data-aware service that discovers records across connected systems, classifies them against your taxonomy, applies policy, and routes ambiguous items to human review before use, sharing, or export.
- · NGOs
- · Institutes
- · Think tanks
- · Advanced R&D labs
- · Donor records
- · Beneficiary files
- · Unpublished research
- · Confidential source material
- · Content signals
- · Metadata
- · Context of use
- · Taxonomy definitions
- · Document repositories
- · Collaboration platforms
- · Databases
- · Cloud object storage
- Discovery pass inventories candidate records across connected sources.
- Classification engine assigns provisional labels using the beneficiary's taxonomy.
- Ambiguous records are visibly routed to a human review channel.
- Confirmed classifications drive downstream routing and policy enforcement.
- · Ambiguous classifications
- · Cross-border transfers
- · Records touching source protection
- · Classification rationale
- · Reviewer confirmation
- · Policy applied on route
- · Policy-Based Access Mediation
- · Compliance and Jurisdictional Mediation
- · Evidence-Grade Audit and Provenance Capture
Ambiguous records route to a human review channel before use.
A collaboration folder receives a draft containing quotations from a protected source. The classifier flags the draft and routes it to a human reviewer before further sharing is permitted.
- · Documented data taxonomy
- · Read access to target systems
- · Named data stewards
- · Maintain the taxonomy
- · Confirm ambiguous items
- · Ratify routing rules
- · Classification confidence varies by content type and available context.
- · The service is not a substitute for records-management or legal review.
Delivery model
Onboarding → Policy Definition → Controlled Rollout → Steady-State Assurance. Every phase produces named evidence artifacts.
- Phase 1Onboarding
Read-only connection to document repositories, collaboration platforms, databases, and object storage. Baseline taxonomy is captured or drafted with data stewards.
- · Source inventory
- · Taxonomy v0
- Phase 2Policy Definition
Classification rules and routing policies are authored per data class, per jurisdiction, and per program. Reviewer channels and thresholds are ratified.
- · Classification ruleset
- · Routing policy pack
- Phase 3Controlled Rollout
Discovery pass runs in observation mode; ambiguous items are routed to human stewards. Enforcement is enabled per source on an agreed schedule.
- · Discovery report
- · Steward review log
- Phase 4Steady-State Assurance
Ongoing discovery, drift monitoring, taxonomy refinement, and quarterly evidence packs for stakeholders.
- · Quarterly classification review
- · Drift report
Beneficiary scenarios
A field investigator uploads a draft containing direct quotes from a protected source into a shared drive. Classification detects source-identifying patterns, restricts the draft to a review channel, and notifies a named data steward before further sharing is possible.
A consortium partner attempts to sync a dataset containing personal health records to an out-of-region collaboration space. Classification recognizes the class and jurisdiction, blocks the sync, and routes the transfer to a compliance reviewer with a linked evidence record.
Engineering detail
Integration model+
Read-mostly connectors to repositories, collaboration platforms, databases, and object storage. Classification runs alongside — never in place of — the beneficiary's records management system.
Data flows+
Content and metadata signals are extracted at rest and in motion, classified against the taxonomy, and either permitted, redacted, quarantined, or routed to a human review channel. Every decision is written to the evidence chain.
Cryptographic components+
Classifiers operate on hashed and minimized signal snapshots where possible. Sensitive content never leaves beneficiary boundaries; models run in-tenant. Classification records are signed.
Logging architecture+
Structured classification records include the taxonomy version, rule references, confidence, reviewer identity where applicable, and lineage back to the source record.
Deployment prerequisites+
A documented data-sensitivity taxonomy (or willingness to draft one), read access to target systems, named data stewards, and a compliance point of contact.
Operational limits+
Classification confidence varies by content type, language, and context. The service is not a substitute for records-management, legal review, or research ethics oversight.
Governance model
- · Taxonomy publication requires data steward ratification.
- · Ambiguous classifications require a named reviewer before use.
- · Cross-border transfers require compliance reviewer sign-off.
- · Source-protection classes require dual review.
Exceptions are recorded with rationale, expiry, and linked evidence. Source-protection exceptions are non-delegable.
Routing decisions are reversible where the downstream system supports it. Classification labels are versioned and can be superseded with full lineage.
The beneficiary owns the taxonomy, steward roster, and source systems. Classification never modifies underlying records without explicit configuration.
Evidence and reporting outputs
- · Classification record with rule references
- · Reviewer confirmation and rationale
- · Taxonomy version reference
- · Routing policy applied
- · Source lineage
- · Exception register entry
- · Discovery report
- · Quarterly classification review pack
Grant scope
- · Connectors to an agreed number of repositories and platforms
- · Taxonomy authoring workshops and initial ruleset
- · Steward onboarding and observation-mode rollout
- · Steady-state discovery, drift monitoring, and quarterly evidence packs
- · Maintain the taxonomy and steward roster
- · Confirm ambiguous items within agreed windows
- · Ratify routing rules through the compliance sponsor
Typical: 4-phase delivery over 10–16 weeks depending on source count and taxonomy maturity.
- · Replacement of the beneficiary's records management system
- · Legal interpretation of jurisdictional obligations
- · Bulk data migration or restructuring
Portfolio interlock
Predecessors, successors, and operational interlocks across the portfolio.
Standalone — no upstream service required.
- · Policy-Based Access Mediation
- · Compliance and Jurisdictional Mediation
- · Evidence-Grade Audit and Provenance Capture
- · Cryptographic Exposure Discovery and PQC Readiness Mapping
Risks and non-claims
Requires validation- · Classifier drift is a real risk without steward feedback loops; steady-state assurance addresses this explicitly.
- · Overly aggressive routing can create reviewer bottlenecks; thresholds are tuned during controlled rollout.
- · The service supports informed decision-making. It does not certify records-management or legal compliance.
