1. Scope & Diagnostic Telemetry Collection
Red River Tech operates RRT SupportOps, an automated Level 1/Level 2 technical support and incident intelligence platform. Our telemetry collectors operate strictly within system operational boundaries.
Explicit Collection Boundaries
Collected Telemetry: Linux kernel dmesg, systemd unit logs, Docker container status, Nginx access/error traces, network socket states, and Prometheus resource counters.
Strictly Excluded: Customer production databases, user passwords, credit card data, personal customer records, and application-level business payloads.
Telemetry streams are only queried upon detection of system anomalies (e.g., OOM killer invocations, HTTP 502/504 spikes, or hung sockets) or explicit engineer dispatch.
2. Client-Side Sanitization & Credential Scrubbing
Before any diagnostic log leaves customer host nodes via the rrt-agent daemon, data passes through a multi-pass deterministic sanitization pipeline.
| Data Category | Detection Pattern | Sanitization Action |
|---|---|---|
| Bearer & OAuth Tokens | High-entropy RFC 6750 token signatures | Irreversibly replaced with [REDACTED_AUTH_TOKEN] |
| Cloud & Database Credentials | AWS keys (AKIA...), DB URI passwords |
Masked with [REDACTED_CREDENTIAL] |
| Internal Hostnames & IPs | RFC 1918 IPv4/IPv6 private subnets | Mapped to persistent anonymized aliases (e.g., node-sg-01.internal) |
| Personal Identifiable Data | Email addresses, user IDs, phone numbers | Hashed or purged before serialization |
3. LLM Context Isolation & Zero Training
RRT SupportOps routes sanitized diagnostic telemetry to Anthropic commercial Claude 3.5 Sonnet API endpoints. Our data governance terms guarantee:
• Zero Model Training: Telemetry, logs, reasoning traces, and diffs are never used to train, fine-tune, or improve frontier models.
• Prompt Caching Segregation: Cached incident runbooks and topology metadata are isolated by cryptographic tenant IDs and automatically invalidated after 5 minutes of inactivity.
• Ephemeral Memory: Volatile runtime contexts inside Claude reasoning nodes are discarded immediately upon returning diagnostic reports.
4. Storage Architecture & Retention Windows
Incident intelligence reports and tool invocation logs are stored in our secure diagnostic cluster located in AWS Lightsail Singapore (AP-SOUTHEAST-1).
Retention Specifications
• Standard Incident Retention: 30 days on AES-256 encrypted volumes, followed by automated cryptoshredding.
• Ephemeral Mode: Customers may configure RETENTION_MODE=0 for immediate post-incident memory purging.
• Cold Storage: We do not transfer operational logs to unencrypted tape or cold storage archives.
5. Subprocessors & Edge Infrastructure
To deliver millisecond-level incident triaging, RRT SupportOps engages tier-1 enterprise infrastructure providers:
| Provider | Role & Scope | Region / Security Standard |
|---|---|---|
| Anthropic, PBC | Frontier LLM inference (Claude 3.5 Sonnet) | US Enterprise API • SOC 2 Type II certified |
| Amazon Web Services (AWS) | Diagnostic compute & log aggregation | Singapore Region • ISO 27001, SOC 1/2/3 |
| Cloudflare, Inc. | DDoS defense, Anycast routing & mTLS edge | Global Edge • PCI-DSS 4.0, SOC 2 Type II |
6. Data Rights & Security Desk
Organizations operating under GDPR, CCPA, or regional data sovereignty regulations may request complete telemetry exports or immediate deletion of historical incident traces.
Direct Email: [email protected] (General: [email protected])
SOC Engineering Desk: Hanoi, Vietnam • Secondary Gateway: Singapore
Verification SLA: Written response within 24 business hours