Skip to content

Data flow description

Planning aid, not a certification or legally sufficient compliance document. Complete in an approved private documentation location. Never insert credentials, key material, or actual restricted records. Unknown required controls block approval.

  • Project / nonsensitive identifier: [fill in]
  • Prepared by / accountable owner: [fill in]
  • Version / date / next review: [fill in]
  • Classification and agreement references: [fill in]
  • Approved evidence location: [fill in]

Systems and transfers

Step Source / owner Destination / owner Data class and version Plaintext or ciphertext Protocol and peer validation Authorization Evidence
Source preparation
Persistent upload
GoCommands download
Decrypt / analyze
Encrypt / return
Release / destruction

Boundaries and copies

  • Diagram with trust boundaries and plaintext locations: [attach/reference]
  • RAM, swap, scratch, notebook checkpoints, spills, logs, crash dumps: [fill in]
  • Replicas, snapshots, backups, trash and geographic placement: [fill in]
  • Metadata visible without decryption: [fill in]
  • External APIs, telemetry, dashboards and allowed network routes: [fill in]
  • Key-release route, distinct from data transfer: [fill in]
  • Linkage operation / custodian and analytical handoff: [fill in]

Review and authorization

  • Unresolved controls / remediation owner / due date: [fill in]
  • Exceptions, approving authority, scope, and expiry: [fill in]
  • Custodian decision / date / evidence reference: [fill in]
  • Institutional decision / date / evidence reference: [fill in]
  • Provider confirmation references: [fill in]
  • Material changes requiring revalidation: [fill in]

For each control, record Supported, Configured, Verified, and Approved separately, with dates and evidence. Do not mark unknown as passed.