Frequently Asked Questions¶
What does Data Focus store from the scanned data?¶
Scanned files are not copied and not stored. Files are read and processed in memory, and only the findings are kept.
For each finding Data Focus records:
- the type of data that was found, for example a national ID number or an e-mail address
- where it was found, meaning the source, the path and the file
- a risk score and the rule that produced the finding
- the detected value, in masked form when masking is enabled
- a short piece of the surrounding text, about 20 characters on each side of the detected value, so a reviewer can judge whether the finding is correct
Surrounding text
The surrounding text comes from the document itself, so it can contain other content from the same file. When masking is enabled it is stored in masked form together with the detected value. It is stored to make review possible and it is shown only to users who are allowed to see findings.
Is masking enabled by default?¶
Yes. Masking is a setting on each scan and it is enabled by default.
While it is enabled, a detected value is stored in masked form — for example 12*******90 — and so is the surrounding text. The value as it appears in the file is never written to the database.
Masking can be turned off for an individual scan. In that case the detected value is stored as it appears in the file, which makes it possible to search over the values themselves. This should only be done when searching over detected values is deliberately part of the scope, because it means real personal data is written to the database.
Where is the data kept?¶
Everything stays on the server where Data Focus is installed. Findings are written to the database that runs inside the same installation. Nothing is sent to Kafein or to any external service.
Optionally, a search index can be enabled to provide full text search across findings. It is disabled by default, and when it is enabled it also runs on the same server.
Are the files that are scanned modified in any way?¶
No. Sources are opened read only. Files are not modified, not moved and not deleted, and no temporary copy is written to disk while a file is being processed.
Two features write outside this rule, and only when they are explicitly requested:
- Masked Copy produces a new, separate copy of a document with the sensitive data masked. The original file is left untouched.
- Write Metadata writes classification results into the metadata of the file or the file system. This is an opt-in action and it can be rolled back.
Who can see an unmasked value?¶
Only users whose role allows it. Viewing the unmasked value of a finding, and opening file content through the viewer, are recorded in the audit log together with the user and the time, so these actions can be traced afterwards.
Does Data Focus need internet access to scan?¶
Not for scanning local file shares and databases, which are reached over the internal network.
Cloud and SaaS sources such as SharePoint, OneDrive, Google Drive, Box, Dropbox and object storage are reached over outbound HTTPS, so those scans need a network route to the provider and working DNS resolution for the provider's endpoints. See Access to Data Sources.