Skip to main content

What leaves Databricks

Requests to the Kyberis API contain exactly:
  • The indicators and queries you enrich — IOC values (IPs, domains, URLs, hashes, emails), CVE IDs, actor, malware, or campaign names, or intel search text you type or select.
  • Environment context you explicitly provide — for example the industry, products, and geography widgets in the CVE prioritization notebook.
  • agent_context metadata — objective and requested-outcome strings, which are static defaults unless you override them, a workflow stage, and random run and step IDs. Nothing here is derived from your table contents.
  • Credentials — the API key on the token-mint call only, and short-lived bearer tokens on enrichment calls.
Not sent, by design: table names, schemas, row contents beyond the selected indicator column, cluster or workspace identifiers, user identities, and notebook code.

What is stored where

Logging and audit

  • Databricks side. Secret reads via dbutils.secrets.get are redacted in notebook output, and secret-scope access and app lifecycle events appear in Databricks audit logs under the secrets and apps event categories, so key access is attributable per user or principal.
  • Kyberis side. Every API call is logged against the API key’s principal with the agent_context run and step IDs. Use a distinct API key per workspace, or per team, so Kyberis-side usage and audit trails attribute cleanly, and pass a meaningful run_id — the helpers generate one per job run — to correlate a Databricks job run with Kyberis-side logs.
  • Error paths. Exception messages produced by this integration never include credential material, and the KyberisCredentials type redacts the secret from repr().

Controls and opt-outs

  • Enrich only the columns you choose; the helpers never scan tables themselves.
  • Set objective widgets and inputs to neutral text if your change management requires it. They are free text and default to static strings.
  • To keep results out of persistent storage, leave output_table empty, which is display-only, and export nothing.