Yazata Security System:
Data Flow & Processing Matrix

Enterprise cyber defense engineered under rigorous Privacy by Design and Security by Default standards. Comprehensive visibility into data lifecycles, storage topologies, recipient boundaries, and statutory retention rules across the entire Yazata ecosystem.

Operator: Illutrium Ltd.
Standard: Regulation (EU) 2016/679 (GDPR)
Appliance Architecture: Layer 2 Transparent Bridge
Remote Ingress: Zero Remote Access

Comprehensive Data Flow & Processing Register

Granular inventory of data categories processed by the Yazata defense system, mapped directly to storage repositories, transmission criteria, retention rules, and GDPR legal bases.

No. Data Category Scope of Processed Data Storage Repository Recipients & Transfer Trigger Retention & Erasure Schedule GDPR Legal Basis
01 Customer Contact Data Full name or legal entity name, designated administrative contact email address, phone number, billing and site installation address, unique hardware ID (UUID). Illutrium Central Cloud
Encrypted central infrastructure
Trust Shield Global Zrt. (Incident handler partner) exclusively upon verified security incidents, attached to manual or automated forensic incident dossiers. Maintained throughout the active service/lease contract, or until statutory accounting/statute of limitations obligations expire. Art. 6(1)(b) GDPR
Contract Performance
02 Appliance Telemetry & Supervision Public IP address, coarse geolocation (country and city level), system timezone, hardware identifier (UUID/MAC address), and custom user-assigned appliance alias. Illutrium Central Cloud
Periodic telemetry log; alias also stored on local Yazata appliance.
Restricted to internal operations (lease asset verification, security firmware update scheduling, timezone-synchronized reporting). Never shared with external third parties. Updated continuously throughout active lease period.
[!] Factory Reset: Permanently purged from server and appliance immediately.
Art. 6(1)(f) GDPR
Legitimate Interest (Asset & Device Integrity)
03 Notification Email Endpoints Client-configured email destinations defined via the local dashboard for weekly statistics, threat summaries, and critical security alarms. Yazata Local Hardware
Stored on local hardware appliance only (absent from central cloud databases).
Upon alert generation, transmitted to Illutrium central transit cluster and dispatched via Cloudflare SMTP relay directly to designated recipients. Editable and deletable at any time by the local administrator.
[!] Factory Reset: Completely erased immediately.
Art. 6(1)(b) / 6(1)(a)
Contractual Alerts / User Configuration
04 Incident Responder Contact Info Dedicated responder name, corporate identity, emergency contact phone, and direct incident ingestion email address of Trust Shield Global Zrt. Yazata Local Appliance
Rendered on local web dashboard and mirrored on central server.
Accessible to local system administrators to facilitate direct emergency incident reporting, mitigation coordination, and rapid SOC escalation. Maintained for the duration of the active SOC incident response agreement. Art. 6(1)(b) GDPR
Contract Performance (Support Readiness)
05 Email Sentry Breach Telemetry Customer-specified corporate email addresses enrolled for surveillance, and their detected dark web exposure/breach status. Illutrium Central Cloud
Breach index state cache
Upon detected exposure, alerts are dispatched to the impacted mailbox, Trust Shield Global Zrt., and configured reporting channels. No raw plaintext email addresses are ever shared (cryptographic k-anonymity validation). Retained until manual removal via the local dashboard or service contract termination. Art. 6(1)(a) / 6(1)(b)
Explicit Opt-In / Protective Service Contract
06 Blocked Threat Events Telemetry of outbound network attempts toward blocked malicious assets (phishing domains, malware hosts, botnet command-and-control servers, malware URLs). Yazata Local Hardware
Rendered locally on the appliance dashboard.
Aggregated, non-personal periodic statistical reports are synchronized with the central Illutrium cluster, then compiled into reports dispatched to Trust Shield SOC and the client. Local rotating retention buffer.
[!] Factory Reset: All local and server-side threat logs permanently purged.
Art. 6(1)(f) GDPR
Legitimate Interest (Network & Information Security)
07 Network & DNS Traffic Logs (Default Protection) Internal DNS query lookups, appliance-level operational logs, and low-level internal system diagnostic logs. Yazata Hardware Exclusively
Air-gapped on physical device
STRICT ZERO TRANSMISSION. Never transmitted externally. Neither Illutrium nor third-party providers have access. Remote ingress is physically and logically disabled; accessible only to local administrators. Strict automated 7-day circular rolling buffer. Records are irrevocably overwritten after 7 days.
[!] Factory Reset: Erased instantaneously.
Art. 6(1)(f) GDPR
Legitimate Interest (Network Integrity)
08 Forensic Network Dumps (Opt-in Diagnostics) Internal client endpoint metadata (internal IP, hostname) attempting to connect to severe malicious destinations, exact timestamps, packet drops, full diagnostic network trace. Yazata Local Hardware
Dispatched to SOC upon explicit manual consent only.
Transferred to Trust Shield Global Zrt. SOC exclusively following explicit, per-incident manual approval and initiation by the customer administrator for deep forensic containment. Maintained strictly until the conclusion of the active security incident investigation, then securely purged.
[!] Factory Reset: Erased instantaneously.
Art. 6(1)(a) / 6(1)(b)
Explicit Authorization / Incident Remediation
09 Internal Subnet Topology (Network Scanner) Active internal IP addresses, resolved hostnames, and discovered listening network ports identified across the protected internal subnet (latest scan output). Yazata Hardware Exclusively
Local device memory
Never transmitted to central cloud infrastructure or external third parties; viewable strictly within the local administrator interface. Only the latest scan outcome is stored (subsequent audit scans completely overwrite prior results).
[!] Factory Reset: Permanently erased.
Art. 6(1)(f) GDPR
Legitimate Interest (Vulnerability Assessment)

Ecosystem Entities, Responsibilities & Systems

Legal classification and technical operational roles of all stakeholders participating in data processing within the Yazata ecosystem under Regulation (EU) 2016/679.

By operating as a Layer 2 transparent bridge rather than an intrusive cloud proxy, Yazata ensures that the subscriber organization retains sovereign control as the Data Controller over internal network telemetry, while technical sub-processors operate under strict Data Processing Agreements (DPAs).

// SOVEREIGN ON-PREMISES DATA CONTROL
Stakeholder / System Deployment / Location GDPR Legal Qualification Operational Role & Duties Security & Legal Guarantees
Client Organization Client Premises
On-premises internal network
Data Controller
For internal network traffic
The organization leasing the Yazata appliance; maintains local notification settings, monitors internal statistics, and grants explicit consent for deep forensic log dispatch. Exclusive sovereignty and access control over local DNS and network logs; per-incident opt-in control over SOC escalations.
Yazata Hardware Appliance Inline Network Bridge
Physical Layer 2 bridge between router & switch
Technical Processing Appliance
On-premises processing tool
Filters real-time local network traffic, neutralizes malware and phishing attempts, enforces 7-day circular DNS retention, and conducts periodic subnet vulnerability scans. Zero Remote Access (no listening ports, no remote administration tunnel); physical debugging only; instant hardware Factory Reset sanitization.
Illutrium Central Infrastructure Central Cloud Infrastructure
Secure EU cloud servers
Data Controller / Processor
Controller (contacts) / Processor (telemetry)
Maintains appliance lease inventories, manages firmware lifecycle updates (IP, timezone, coarse location), powers Email Sentry breach state, and triggers transactional notification transit. Implementation of cryptographic k-anonymity for breach lookups; automated data deletion upon contract expiry or factory reset.
Trust Shield Global Zrt. External Security Partner
Budapest, Hungary (EU)
Sub-Processor (SOC)
Managed Security Operations Center
Analyzes escalated security incidents, conducts threat forensics, assists in threat neutralization, and provides expert incident containment response. Executed Data Processing Agreement (DPA) and strict Non-Disclosure Agreement (NDA); receives data solely via aggregated reports or manual opt-in customer approval.
Cloudflare, Inc. Global Edge Network
EU / Global transit relays
Technical Sub-Processor
Email Delivery Transit Provider
Provides technical SMTP routing and email delivery infrastructure for automated system reports, threat notifications, and incident advisories. Standard Contractual Clauses (SCCs) / EU-U.S. Data Privacy Framework compliance; strictly transient transmission without persistent data storage.

Technical & Organisational Measures (TOMs)

Embedded Privacy by Design and Security by Default safeguards fulfilling Articles 5, 17, 25, and 32 of Regulation (EU) 2016/679.

Security Principle Technical Architecture & Implementation Statutory GDPR Benefit Impacted Data Scope
K-Anonymity Cryptographic Defense Email Sentry never transmits raw email addresses to third-party databases. Credential exposure lookups use cryptographic hashing and a k-anonymity mathematical model, mathematically preventing external reverse-engineering. Art. 25 & Art. 32 GDPR
Privacy by Design, Pseudonymization & Encryption
Email Sentry monitored identifiers & breach telemetry
Zero Remote Access Ingress Yazata hardware appliances present zero listening inbound ports to WAN (no open ports, no listening SSH daemon, no external management console). Diagnostic maintenance requires physical on-site access. Art. 32 GDPR
Protection against unauthorized access & intrusions
Local appliance, internal network traffic & local log stores
Factory Reset Complete Sanitization Executing a physical or local Factory Reset immediately wipes all local configuration profiles, credentials, telemetry buffers, and operational logs, and also notifies the central servers to drop related user data as soon as possible. Art. 17 & Art. 5(1)(e) GDPR
Right to Erasure & Storage Limitation
All processed datasets across appliance and cloud registries
7-Day Rolling Circular Buffer Detailed DNS lookups and network traffic logs are hosted strictly in local volatile appliance memory/storage. Records are automatically, irrevocably overwritten after a 7-day rolling window. Art. 5(1)(c) & Art. 5(1)(e)
Data Minimisation & Storage Limitation
DNS query telemetry, traffic flow stats & system logs
Explicit User-Authorized Escalation Granular traffic dumps necessary for in-depth threat forensic analysis (internal client IP, target host, dropped packet counts) can only be dispatched to Trust Shield Global Zrt. via explicit, per-incident manual approval by the client administrator. Art. 6 & Art. 5(1)(c) GDPR
Explicit Consent & Strict Purpose Limitation
Forensic network captures & threat analysis dossiers

Data Pipeline & Topology: From Ingestion to Dispatch

End-to-end data lifecycle map showing transparent Layer 2 on-premises filtering, localized retention barriers, and conditional cloud escalation channels:

// YAZATA DEFENSE SYSTEM — DATA FLOW PIPELINE & TOPOLOGY MATRIX

[ INTERNAL CLIENT ENDPOINTS ] ──► (Laptops, Workstations, Mobile devices, Internal NAS, IoT)
                                  │ (Standard Ethernet & Wi-Fi network traffic)
                                  ▼
┌─────────────────────────────────────────────────────────────────────────────┐
│  YAZATA HARDWARE SHIELD (PHYSICAL LAYER 2 TRANSPARENT INLINE BRIDGE)        │
│  • Real-time DNS Filtering & Malicious Domain Neutralization                 │
│  • Zero Remote Access Ingress (No open WAN ports / No inbound management)   │
│  • Air-gapped 7-day circular rolling log buffer (Automated overwrite)       │
└──────────────┬──────────────────────────────────────────────┬───────────────┘
               │                                              │
  [ Periodic Aggregated Telemetry ]                [ High-Severity Incident Trigger ]
  [ Device heartbeat + Anonymized stats ]           [ Requires explicit manual approval ]
               │                                              │
               ▼                                              ▼
[ ILLUTRIUM CENTRAL CLUSTER ]                 [ TRUST SHIELD GLOBAL ZRT. SOC ]
  • Lease inventory & updates                     • Expert forensic threat triage
  • Email Sentry (k-anonymity)                    • Real-time incident containment
               │
               │ (Automated alert transit via Cloudflare SMTP)
               ▼
[ CLIENT SECURITY CONTACT & DEDICATED INCIDENT RESPONDER DISPATCH ]

This architecture guarantees that private intranet traffic never escapes client custody by default, providing mathematical and infrastructural certainty for compliance officers and enterprise CISOs.