Non-sensitive examples only
Do not use personal, confidential, regulated, proprietary, material non-public or trading-sensitive information. Use built-in synthetic samples where possible.
This page distinguishes implemented website controls, public-demo restrictions and customer-project security choices. SDS does not claim third-party certifications that have not been independently evidenced.
The public Foundry processes small samples in the browser and does not intentionally upload the dataset to SDS.
Do not use personal, confidential, regulated, proprietary, material non-public or trading-sensitive information. Use built-in synthetic samples where possible.
Deploy behind Hostinger TLS. Security headers deny framing, restrict browser capabilities and reduce content-type ambiguity.
Administrator passwords use PHP secure password hashing. Sessions use HTTP-only, SameSite cookies and regenerate after login.
Content and consultation actions use server-side validation, CSRF tokens, limits and protected JSON storage in the shared-hosting edition.
The Foundry accepts only small CSV and JSON examples, checks extension and size, reads locally and never executes uploaded content.
Consultation and optional assessment submissions store business contact details and context for follow-up. Operators should periodically export and remove records no longer needed.
| Area | SDS project principle | Decision evidence |
|---|---|---|
| Access | Least privilege, role and purpose context | Access model and reviewed authorization tests |
| Lineage | Retain source, mapping, transformation and rule provenance | Traceable evidence path |
| Deployment | Customer cloud, private environment or approved managed platform | Architecture and responsibility matrix |
| Backup & recovery | Versioned artifacts and tested recovery matched to criticality | Recovery procedure and test record |
| Vulnerability management | Dependency, configuration and code review appropriate to the stack | Findings, ownership and remediation status |
| Third parties | Disclose providers and minimize data transfer | Vendor inventory and processing purpose |
Keep source, entity, relationship, rule and model context available for review.
Retrieval and agent actions should honor purpose, sensitivity and access boundaries.
Test groundedness, completeness and harm against real competency questions—not a universal accuracy claim.
To request current security documentation or discuss a private deployment, contact info@semanticdataservices.com.