Privacy methodology
Aggregate security telemetry
HOL Guard does not currently publish aggregate product telemetry. This page documents the rules that must be satisfied before any public cohort is released.
Population and claims
Any future result must be labeled observations among explicitly opted-in HOL Guard users. It must not be described as prevalence among all AI users or all AI security incidents.
Release safeguards
- • Collection is explicit opt-in and local protection cannot depend on participation.
- • Raw prompts, commands, source code, file paths, secrets, credentials and identity fields are outside the aggregate event contract.
- • A publishable cell requires at least 10 observations and 10 distinct contributors, with complementary suppression where one hidden cell could otherwise be reconstructed.
- • Raw opt-in event metadata is retained for at most 30 days; internal aggregates are retained for at most 180 days.
- • Re-identification checks, methodology versioning, named reviewer roles, and legal/privacy/security approval are required before public release.
Legal review
Status: required not completed. Public cohort language requires documented legal/privacy review. Code completion is not legal approval.
Differential privacy
Status: evaluated not deployed. Do not claim differential privacy. The first release gate uses data minimization, explicit opt-in, contributor thresholds, and complementary suppression. Re-evaluate DP before expanding dimensions, frequency, or cohort sensitivity.
Comparison neutrality
Comparisons must apply the same published metric to all products, preserve unfavorable/null results, distinguish unknown from unsupported, and never accept payment for ranking or recommendation placement.
Method version 1.0.0. Public telemetry remains disabled until all release approvals are documented.