Data sensitivity
Data sensitivity (D-class) describes how sensitive conversation content is. Steinkauz uses five levels from public to critical.
Sensitivity defaults and override rules are configured per active context in Settings → Routing policy.
Levels
| Class | Label | Typical use |
|---|---|---|
| D0 | Public | Non-sensitive content; broad provider choice when the matrix allows |
| D1 | Internal | Internal business data |
| D2 | Confidential | Confidential business or customer data |
| D3 | Restricted | Highly restricted or regulated data |
| D4 | Critical | Highest sensitivity; strictest routing |
Ordering is strict: D0 < D1 < D2 < D3 < D4.
Effective sensitivity (routing)
For each chat send, Steinkauz computes effective data sensitivity as the maximum of:
- The session floor (stored on the thread; see Auto and Manual modes below)
- Any attachment data sensitivity on files referenced in the current request
Your message and file defaults are not re-applied on every send. The message default sets the initial session floor when a conversation starts in Auto mode. The file default pre-selects classification on new uploads.
Where D-class is set
- Message default — Settings → Routing policy. Auto-mode starting floor for new conversations. Platform default: D0 (Public).
- File default — Settings → Routing policy. Pre-selected sensitivity on new uploads. Platform default: D0 (Public).
- Session floor — Stored per chat thread. In Auto mode it can rise when attachments or provider selection require it; it does not fall automatically.
- Attachments — Each uploaded Chat File carries a D-class. Edit it from Files in the chat sidebar (or on the Chat Attachment before send); lowering below the context default (when allowed) or below the previous level requires a reason and is audited.
- Manual mode — The shield control in chat fixes the session floor to your chosen D-class, subject to override policy.
Auto vs Manual (chat shield)
- Auto — Session floor starts at your message default and may rise. Provider environments can also raise the floor when your matrix allows the recommended D×E pair.
- Manual — You choose a fixed floor. Levels below the message default require an explicit policy allowance and audit reason. Only providers permitted by your routing matrix for that sensitivity appear in the model picker.
Derived artifacts
Outputs generated from sensitive inputs inherit the highest source sensitivity — including transcripts, summaries, embeddings, tool inputs/outputs, and images created from restricted context. Routing checks use that inherited level when follow-up steps include those artifacts.
Enforcement
The server computes effective D-class before inference and checks it against your routing matrix and the provider’s E-class. Blocked sends are rejected with guidance on how to resolve the mismatch.
Related topics
- Data routing policy — matrix overview and settings
- Files & attachments
- Provider environment — E-class on providers