Skip to main content

Data classification guidance

Before placing information into Starfire, decide what kind of data it is and whether the selected context is appropriate for it.

Practical categories

Public

Information intended for unrestricted public distribution. Examples: published documentation, public marketing copy, open-source code.

Internal

Business information intended for authorized team use but not necessarily public. Examples: internal procedures, draft plans, non-public project notes.

Confidential

Information whose exposure could cause business, customer, contractual, or privacy impact. Examples: unpublished product plans, private source code, customer records, sensitive financial information.

Secret / credential

Information that directly grants access. Examples: passwords, API keys, tokens, private keys. Do not place secrets into normal Starfire AI context.

Choose the context

Durable vs temporary context

A confidential file attached to one chat and the same file indexed into organization Knowledge have different reuse and access implications. Use the narrowest lifetime and audience required by the task.

Organization policy

Organizations can apply their own data-handling rules in addition to Starfire product permissions. Team policy should decide which categories are permitted in Projects, Knowledge, integrations, or AI workflows.

Developer integrations

When an API or webhook sends data from Starfire into another system, the receiving system’s security and retention rules matter too.
This page provides product-usage guidance, not a replacement for your organization’s legal, regulatory, contractual, or formal information-security classification program.