BellPath by DSBBellPathOSSecurity
Privacy + AI + Plaid controls

Data Classification

Classification rules for BellPathOS data, client-owned AI keys, local storage, and bank/brokerage connector data.

SOC 2 readinessLocal-first privacyClient-owned secretsCloudflare hardened
Data classification

Know what BellPathOS is handling

This is the operating rulebook for privacy, AI prompts, Plaid, export/delete, and future SOC 2 evidence.

ClassExamplesStorage ruleAI rule
Publicmarketing copy, pricing pages, blog postspublic siteallowed if non-sensitive
Local Onlysetup profile, demo mode, preferencesbrowser local storageonly if user submits
Sensitivedebt balances, paycheck notes, workplace issue logs, family stability datalocal first; exportable by clientuser consent required
ConfidentialAI API key vault metadata, license backup, private contact detailsencrypted or local onlydo not send unless necessary
RestrictedPlaid secret, Plaid access token, bank routing/account data, raw brokerage account tokensnever in public browser JavaScript; Worker secret/KV/D1 onlynever send by default
AI Sharedprompts sent to client selected model providerprovider dependentexplicit notice and client-owned key
Plaid Connectedaccount names, balances, transactions, holdingsclient-owned Worker; least necessary datasummarized only with consent
Restricted data rule

Never put Plaid secrets in public browser code

Client-owned Plaid is supported, but the Plaid secret belongs in a Cloudflare Worker secret or other backend secret manager. BellPathOS should store only the client-owned Worker URL and non-secret connector preferences in the browser.

BellPathOS Menu
HomeCommand centerAppsLauncherClient SetupProfile, keys, connectorsSecurity CenterSOC 2 readinessSOC 2 ReadinessControl mapSecurity CheckBrowser checksData ControlExport/deleteTrust CenterPrivacy & securitySupportContact BellPath