What leaves Databricks
Requests to the Kyberis API contain exactly:- The indicators and queries you enrich — IOC values (IPs, domains, URLs, hashes, emails), CVE IDs, actor, malware, or campaign names, or intel search text you type or select.
- Environment context you explicitly provide — for example the industry, products, and geography widgets in the CVE prioritization notebook.
agent_contextmetadata — objective and requested-outcome strings, which are static defaults unless you override them, a workflow stage, and random run and step IDs. Nothing here is derived from your table contents.- Credentials — the API key on the token-mint call only, and short-lived bearer tokens on enrichment calls.
What is stored where
Logging and audit
- Databricks side. Secret reads via
dbutils.secrets.getare redacted in notebook output, and secret-scope access and app lifecycle events appear in Databricks audit logs under thesecretsandappsevent categories, so key access is attributable per user or principal. - Kyberis side. Every API call is logged against the API key’s principal with
the
agent_contextrun and step IDs. Use a distinct API key per workspace, or per team, so Kyberis-side usage and audit trails attribute cleanly, and pass a meaningfulrun_id— the helpers generate one per job run — to correlate a Databricks job run with Kyberis-side logs. - Error paths. Exception messages produced by this integration never include
credential material, and the
KyberisCredentialstype redacts the secret fromrepr().
Controls and opt-outs
- Enrich only the columns you choose; the helpers never scan tables themselves.
- Set
objectivewidgets and inputs to neutral text if your change management requires it. They are free text and default to static strings. - To keep results out of persistent storage, leave
output_tableempty, which is display-only, and export nothing.
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=66da6f97e851defcb12af05b800a8a27)
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=37df025ce7a3cc54dd90f8edad1cf54f)