Proxima
by Proximaagents

InfoSec appendix

Security posture for the diagnostic path.

A review-ready appendix for IT, InfoSec, procurement and operations, to read before approving a diagnostic or any later technical validation.

Review note. This page describes design intent and review questions. It avoids certification claims and should be validated against each customer's policy before production integration.

For operations teams

Wherever we can, we start with sample or read-only data. Your team decides what is shared, where it is processed and who can touch it. No live system action is approved as part of the review.

Boundary

Diagnostic access starts narrow.

Where possible the diagnostic uses sample, anonymized or read-only sources. Approving the diagnostic does not approve write access to production. Those are two separate decisions.

Audit

Every phase needs evidence.

Recommendations, approvals, actions and recovery records should all be captured before you move from understanding the work (Observe), to suggesting without acting (Shadow), to a person approving each action (HITL), or to proven routine actions running within agreed limits (Autopilot).

Data handling by phase

AreaDiagnostic defaultBefore production validation
Data scopeLimited samples, time-boxed extracts, or anonymized records where the pattern remains valid.Named systems, fields, residency needs, masking rules, and retention period approved by customer IT.
AccessRead-only access or customer-provided files for the diagnostic question.Least-privilege service identities, customer-managed secrets, owner, expiry, and revocation path.
AuditabilityWorkshop artifacts, assumptions, and recommendation packet.Required input, rules evaluated, operating-limit result, approval, final action, and documented recovery or escalation evidence.
Regulated workflowsDPDP-aware and customer-policy led review language.Keep sensitive execution inside the customer environment unless IT approves another path.

Phased trust

Responsibility increases through four checks.

  • ObserveUnderstand the workInspect samples, logs and process records without changing a single customer system.
  • ShadowSuggest, don’t actMeasure our suggestions against the team’s real decisions and see exactly where the two disagree.
  • Human approvalYour team decidesSupervisors approve, edit or reject each prepared action before it runs.
  • Controlled automationAutomate what has proved safeOnly customer-approved action categories may run automatically after the operating limits, monitoring and response procedures are agreed and tested.

Review agenda

Questions for IT review