Security and data

A connection is not a blank cheque.

Before connecting Sorvek, your team should be able to review the scope, permissions and what can actually happen in your environment.

Understand permissions by use case.

Not all connections do the same thing. We make this distinction visible so you can review it before granting consent.

Read-only

Read and connect signals.

Discovery and posture connections, along with Sorvek Bridge, read the authorized scope. Sorvek Bridge cannot take any action or make changes.

Ticket creation

Jira is a separate action.

The Jira connection can create tickets from findings. Review its purpose and scope before sending; actions can be previewed.

Browser extension

The policy applies in the browser.

Depending on the selected rule, the extension can log, warn, request justification, block, redact or redirect usage.

Prepare the review

Questions to ask before the first consent.

Your organization remains responsible for deciding the scope, retention, authorized people and response rules.

Which source is connected?

Identify the data needed for the subject you want to review, without expanding the scope by default.

Which permission is requested?

Read the connector’s permissions and distinguish observation from an action in another system.

Which behaviour is enabled?

For a playbook, browser rule or Jira, check the dry run, target and possible follow-up before activation.

Hosted in Canada

Review processing, data residency, retention and subcontracting arrangements with your team before deployment. Request the information needed for your internal review.

Your review starts with your own questions.

Involve your IT, security and privacy teams from the start. We can help distinguish the features, but your organization approves its own scope.