Data, collection and responsibilities

01 · WHAT HIIH MAY COLLECT

The data classes a deployment may produce.

Network & protocol observations
Source context, connection metadata and service interaction supplied to a HIIH target during hostile contact.
Authentication material
Usernames, passwords, tokens, keys or other material an actor presents to a HIIH target — captured as the adversary supplies it.
Session activity
Commands, terminal activity, files, tools and post-access behavior on supported targets, where the engagement depth allows.
Evidence artifacts
Captured binaries, session recordings, screenshots or related artifacts, where the target and engagement support them.
Structured HIIH Findings
Observed facts, assessment, confidence, relevance, recommended actions and links to the supporting observations behind them.
Customer-supplied context
Exposure profile, mission question, approved target characteristics and delivery configuration provided to scope the Surface.
Data presented by an adversary may concern third parties, victims or compromised infrastructure. Handling, access, retention, redaction and export therefore belong to the engagement design and contract — not to a blanket claim that the customer “owns everything.”
02 · DATA HANDLING AND ACCESS PRINCIPLES

Principles for diligence; contractual detail sits in the data processing agreement (DPA).

Purpose limitation — data are collected to operate the Surface, analyze hostile activity, produce Findings and support agreed outputs.
Access limitation — access is restricted to authorized OHIIHO personnel, approved partner operators and customer users according to the engagement model.
Retention by engagement — retention periods depend on the data class, deployment and contract.
Redaction and minimization — sensitive third-party data are minimized or redacted for briefings, Research and redistribution where required.
Controlled export — export rights and formats are engagement-specific. Public Research is not an automatic downstream use of customer data.
Customer separation — customer-specific evidence and outputs are logically separated; any future cross-Surface correlation requires a separately governed path.
Publication review — Research publication requires sanitization and approval appropriate to provenance and sensitivity.
Data handling is defined for the deployment and documented during diligence. The public page states principles, not a universal retention period or jurisdiction guarantee — those are fixed per engagement.
03 · RESPONSIBILITY MODEL

OHIIHO operates the engagement environment. You define the mission and use the intelligence.

AreaOHIIHOMSSP / partnerCustomer
Surface design & operationprimarycontributes service contextapproves mission and scope
Engagement environmentbuilds, hosts and managesdoes not operate hostile infrastructure unless agreeddoes not host hostile execution by default
Exposure configurationsupplies approved mechanismsmay implement with customerapproves and controls customer-side change
Evidence & Findingscollects and structuresconsumes, triages and packages for serviceconsumes under agreed access
SOC responseplatform / research supportL1/L2 and client workflow in partner modelacts through its security process
Data governanceimplements agreed controlsfollows service obligationsapproves contractual terms and authorized users

Typical managed model. The exact split may vary by contract.

HIIH does not ask every customer or MSSP to become a honeypot operator. OHIIHO operates the specialized engagement environment. The customer or partner defines the mission, approves the exposure and uses the resulting signal inside its existing security process.

For partners · Delivery & integrations