Evidence standards and handling
What to include, what to redact, supported files, and prompt-injection hygiene.
Last updated · September 2026
On this page
The quality of analysis is bounded by the quality and provenance of the input. Treat evidence as an engineering artifact with a source, time range, integrity context, and known limitations.
| Include | Remove or redact |
|---|---|
| Source system and collection method | Passwords and API keys |
| UTC offset or timezone | Private keys and session tokens |
| Relevant timestamps and identifiers | Unrelated personal information |
| Asset or account names | Customer data outside the case scope |
| What the artifact does not contain | Secrets embedded in source code |
| Links to the original case or ticket | Content you are not authorized to disclose |
Supported evidence files
The workspace accepts plain-text evidence with .txt, .log, .json, .csv, .md, .yaml, and .yml extensions up to 2 MB. Binary files are not analyzed by the current workspace upload flow.
Prompt injection in evidence
Logs, tickets, web pages, and source files can contain text that looks like instructions. Treat all attached content as untrusted data. Your analyst request and organizational process define the task; evidence does not grant authority or override controls.
Was this page helpful?

