Spec: data loss prevention and mail flow rules #97

Merged
jcoffey-dev merged 3 commits from spec/dlp-mail-flow-rules into main 2026-09-28 23:58:53 +00:00
Owner

Phase 1 of DLP and the rule builder, specced together: docs/spec/features/dlp-and-mail-flow-rules.md.

  • One native rule engine at DATA, after the system Sieve script and before DKIM signing; hand-written Sieve untouched.
  • DLP on outgoing mail: counted detectors (payment cards with Luhn, IBAN mod 97, US SSN, word lists, patterns) plus attachment conditions; block, warn with an audited override, or hold for review.
  • Hold keeps the message in the queue unscheduled with a review record, so the queue format is unchanged across a rolling upgrade.
  • Audit records name the rules and counts, never the matched text.
  • Six questions under For John; nothing is built until they are answered.
Phase 1 of DLP and the rule builder, specced together: `docs/spec/features/dlp-and-mail-flow-rules.md`. - One native rule engine at DATA, after the system Sieve script and before DKIM signing; hand-written Sieve untouched. - DLP on outgoing mail: counted detectors (payment cards with Luhn, IBAN mod 97, US SSN, word lists, patterns) plus attachment conditions; block, warn with an audited override, or hold for review. - Hold keeps the message in the queue unscheduled with a review record, so the queue format is unchanged across a rolling upgrade. - Audit records name the rules and counts, never the matched text. - Six questions under **For John**; nothing is built until they are answered.
jcoffey-dev added 1 commit 2026-09-28 22:57:58 +00:00
Spec: data loss prevention and mail flow rules
ci / fork-checks (pull_request) Successful in 46s
ci / build (pull_request) Successful in 4m52s
2a851ea230
Phase 1: one native rule engine at DATA, after the system Sieve script,
for both DLP policies and transport rules. DLP checks outgoing mail
with counted detectors (payment cards, IBAN, US SSN, word lists,
patterns) and blocks, warns with an audited override, or holds for
review. Held mail stays in the queue unscheduled, with its own review
record, so the queue's stored format is unchanged. Matches go to the
audit log without the matched text. Six questions for John at the end.
jcoffey-dev added 1 commit 2026-09-28 23:04:35 +00:00
Spec: John's answers, and the detector catalog answer 6 asks for
ci / fork-checks (pull_request) Successful in 19s
ci / build (pull_request) Successful in 7m23s
3fadf82909
All six settled as recommended. Answer 6 ("and any other recognized and protected PII") becomes a catalog of identifiers with published formats and checks, grouped by region, each either checked by its check digit or counted only beside a corroborating word, plus templates named for what they find. Data with no number to find is covered by word lists and not claimed as detection. Office documents are read; PDF counts as can't be inspected.
jcoffey-dev added 1 commit 2026-09-28 23:41:42 +00:00
Spec: approved
ci / fork-checks (pull_request) Successful in 46s
ci / build (pull_request) Successful in 16m58s
2b45a2e412
jcoffey-dev merged commit f7fb115a0f into main 2026-09-28 23:58:53 +00:00
jcoffey-dev deleted branch spec/dlp-mail-flow-rules 2026-09-28 23:58:53 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: inbuxa/inbuxa-server#97