Skip to content
HEKA — See First. Defend First. Powered by KRYOS XS Hypercube
Data protection

Sensitive Data Classification and Routing

A data-aware service that discovers records across connected systems, classifies them against your taxonomy, applies policy, and routes ambiguous items to human review before use, sharing, or export.

Mission problem
Sensitive information often lives in inconsistent silos with unclear ownership, creating exposure during collaboration, export, or research publication.
Who it protects
  • · NGOs
  • · Institutes
  • · Think tanks
  • · Advanced R&D labs
Sensitive assets involved
  • · Donor records
  • · Beneficiary files
  • · Unpublished research
  • · Confidential source material
Required inputs
  • · Content signals
  • · Metadata
  • · Context of use
  • · Taxonomy definitions
Connected systems
  • · Document repositories
  • · Collaboration platforms
  • · Databases
  • · Cloud object storage
How the service works
  1. Discovery pass inventories candidate records across connected sources.
  2. Classification engine assigns provisional labels using the beneficiary's taxonomy.
  3. Ambiguous records are visibly routed to a human review channel.
  4. Confirmed classifications drive downstream routing and policy enforcement.
Human-review points
  • · Ambiguous classifications
  • · Cross-border transfers
  • · Records touching source protection
Evidence produced
  • · Classification rationale
  • · Reviewer confirmation
  • · Policy applied on route
Service interlocks
  • · Policy-Based Access Mediation
  • · Compliance and Jurisdictional Mediation
  • · Evidence-Grade Audit and Provenance Capture
Sensitive Data Classification River
Discover
Classify
Validate
Apply Policy
Route
Log
Donor record
Beneficiary file
Unpublished research
Public report
Ambiguous draft

Ambiguous records route to a human review channel before use.

Illustrative scenario
Illustrative: research draft flagged for source-protection review

A collaboration folder receives a draft containing quotations from a protected source. The classifier flags the draft and routes it to a human reviewer before further sharing is permitted.

Deployment prerequisites
  • · Documented data taxonomy
  • · Read access to target systems
  • · Named data stewards
Beneficiary responsibilities
  • · Maintain the taxonomy
  • · Confirm ambiguous items
  • · Ratify routing rules
Limitations and non-claimsRequires validation
  • · Classification confidence varies by content type and available context.
  • · The service is not a substitute for records-management or legal review.
Frequently asked
Does the platform move our data?
By default, the overlay is read-mostly and applies policy in place. Movement occurs only when explicitly configured.
What if the taxonomy is incomplete on day one?
Discovery surfaces gaps; the taxonomy evolves iteratively with data stewards through the review channel.
Can classifications be re-reviewed?
Yes. Every classification is versioned and can be re-evaluated by data stewards with full lineage preserved.

Delivery model

Onboarding → Policy Definition → Controlled Rollout → Steady-State Assurance. Every phase produces named evidence artifacts.

4-Phase Delivery Timeline
  1. Phase 1
    Onboarding

    Read-only connection to document repositories, collaboration platforms, databases, and object storage. Baseline taxonomy is captured or drafted with data stewards.

    • · Source inventory
    • · Taxonomy v0
  2. Phase 2
    Policy Definition

    Classification rules and routing policies are authored per data class, per jurisdiction, and per program. Reviewer channels and thresholds are ratified.

    • · Classification ruleset
    • · Routing policy pack
  3. Phase 3
    Controlled Rollout

    Discovery pass runs in observation mode; ambiguous items are routed to human stewards. Enforcement is enabled per source on an agreed schedule.

    • · Discovery report
    • · Steward review log
  4. Phase 4
    Steady-State Assurance

    Ongoing discovery, drift monitoring, taxonomy refinement, and quarterly evidence packs for stakeholders.

    • · Quarterly classification review
    • · Drift report

Beneficiary scenarios

Illustrative
Human Rights NGO with source-identifying material in shared drives

A field investigator uploads a draft containing direct quotes from a protected source into a shared drive. Classification detects source-identifying patterns, restricts the draft to a review channel, and notifies a named data steward before further sharing is possible.

Illustrative
Research consortium with jurisdictionally sensitive data

A consortium partner attempts to sync a dataset containing personal health records to an out-of-region collaboration space. Classification recognizes the class and jurisdiction, blocks the sync, and routes the transfer to a compliance reviewer with a linked evidence record.

Engineering detail

Integration model+

Read-mostly connectors to repositories, collaboration platforms, databases, and object storage. Classification runs alongside — never in place of — the beneficiary's records management system.

Data flows+

Content and metadata signals are extracted at rest and in motion, classified against the taxonomy, and either permitted, redacted, quarantined, or routed to a human review channel. Every decision is written to the evidence chain.

Cryptographic components+

Classifiers operate on hashed and minimized signal snapshots where possible. Sensitive content never leaves beneficiary boundaries; models run in-tenant. Classification records are signed.

Logging architecture+

Structured classification records include the taxonomy version, rule references, confidence, reviewer identity where applicable, and lineage back to the source record.

Deployment prerequisites+

A documented data-sensitivity taxonomy (or willingness to draft one), read access to target systems, named data stewards, and a compliance point of contact.

Operational limits+

Classification confidence varies by content type, language, and context. The service is not a substitute for records-management, legal review, or research ethics oversight.

Governance model

Approval gates
  • · Taxonomy publication requires data steward ratification.
  • · Ambiguous classifications require a named reviewer before use.
  • · Cross-border transfers require compliance reviewer sign-off.
  • · Source-protection classes require dual review.
Exception handling

Exceptions are recorded with rationale, expiry, and linked evidence. Source-protection exceptions are non-delegable.

Rollback paths

Routing decisions are reversible where the downstream system supports it. Classification labels are versioned and can be superseded with full lineage.

Beneficiary control boundaries

The beneficiary owns the taxonomy, steward roster, and source systems. Classification never modifies underlying records without explicit configuration.

Evidence and reporting outputs

  • · Classification record with rule references
  • · Reviewer confirmation and rationale
  • · Taxonomy version reference
  • · Routing policy applied
  • · Source lineage
  • · Exception register entry
  • · Discovery report
  • · Quarterly classification review pack

Grant scope

Included
  • · Connectors to an agreed number of repositories and platforms
  • · Taxonomy authoring workshops and initial ruleset
  • · Steward onboarding and observation-mode rollout
  • · Steady-state discovery, drift monitoring, and quarterly evidence packs
Beneficiary responsibilities
  • · Maintain the taxonomy and steward roster
  • · Confirm ambiguous items within agreed windows
  • · Ratify routing rules through the compliance sponsor
Timeline

Typical: 4-phase delivery over 10–16 weeks depending on source count and taxonomy maturity.

Explicit exclusions
  • · Replacement of the beneficiary's records management system
  • · Legal interpretation of jurisdictional obligations
  • · Bulk data migration or restructuring

Portfolio interlock

Portfolio Interlock Web
01Access02Data class.03Threat corr.04Workflow05Evidence06Compliance07Reporting08Vendor09PQC readiness10Scenario/IR10-serviceportfolio

Predecessors, successors, and operational interlocks across the portfolio.

Natural predecessors

Standalone — no upstream service required.

Natural successors
  • · Policy-Based Access Mediation
  • · Compliance and Jurisdictional Mediation
Operational interlocks
  • · Evidence-Grade Audit and Provenance Capture
  • · Cryptographic Exposure Discovery and PQC Readiness Mapping

Risks and non-claims

Requires validation
  • · Classifier drift is a real risk without steward feedback loops; steady-state assurance addresses this explicitly.
  • · Overly aggressive routing can create reviewer bottlenecks; thresholds are tuned during controlled rollout.
  • · The service supports informed decision-making. It does not certify records-management or legal compliance.
Next
Discuss this service in your context