Understanding metadata sensitivity
While Security Incident Response doesn't collect your application data, the metadata it collects across all three categories can reveal sensitive information about your environment and potentially your users. Consider the following examples:
-
Resource names such as
patient-database-prodorfinancial-records-2026indicate the purpose and sensitivity of resources. -
DNS queries like
user12345.internal.app.commay contain user identifiers or internal system information. -
API call patterns can reveal business processes and operational workflows.
Organizations in regulated industries should evaluate whether this metadata falls under their compliance requirements, even though it isn't the regulated data itself.