Data classification guidance
Before placing information into Starfire, decide what kind of data it is and whether the selected context is appropriate for it.Practical categories
Public
Information intended for unrestricted public distribution. Examples: published documentation, public marketing copy, open-source code.Internal
Business information intended for authorized team use but not necessarily public. Examples: internal procedures, draft plans, non-public project notes.Confidential
Information whose exposure could cause business, customer, contractual, or privacy impact. Examples: unpublished product plans, private source code, customer records, sensitive financial information.Secret / credential
Information that directly grants access. Examples: passwords, API keys, tokens, private keys. Do not place secrets into normal Starfire AI context.Choose the context
Durable vs temporary context
A confidential file attached to one chat and the same file indexed into organization Knowledge have different reuse and access implications. Use the narrowest lifetime and audience required by the task.Organization policy
Organizations can apply their own data-handling rules in addition to Starfire product permissions. Team policy should decide which categories are permitted in Projects, Knowledge, integrations, or AI workflows.Developer integrations
When an API or webhook sends data from Starfire into another system, the receiving system’s security and retention rules matter too.This page provides product-usage guidance, not a replacement for your organization’s legal, regulatory, contractual, or formal information-security classification program.
