Security Assistant
Find information buried in your compliance docs through an easy-to-use question and answer interface
Written By Micah
Numerous distinct roles contribute to maintaining an effective compliance program, meaning that a wealth of information security details are captured within your organization's Strike Graph platform. But, unless you are deeply involved in everyone's business, it can be hard to know where to locate valuable nuggets of information.
We built Security Assistant to help you surface the critical components of your compliance evidence through an easy-to-use, chat-like experience. Use Security Assistant to find intel on your policies, procedures, settings, and other compliance-related questions. This can be especially helpful for routine refreshers of compliance requirements, answering vendor compliance questionnaires, or confirming details of compliance requirements.
How it works
If you have access to Security Assistant, you will see it in the main navigation under Trust Assets (if you do not, reach out to your Customer Success Manager to ask about an upgrade). At this time, Security Assistant is only available to users with Manager permissions.
Security Assistant answers questions from the content of your organization's evidence attachments. Simply type in a question, and Security Assistant will return an answer, as well as the top three direct sources where the information was found.
Security Assistant also keeps track of the questions that have been asked, so switch to the History tab to review past answers from other users within your organization.
Note: Security Assistant is not designed to answer questions about how to use the Strike Graph platform. Please direct any platform related queries to our other articles and collections, or to the Intercom chat feature.
Built with Security and Privacy in mind
We take our customer's security and privacy very seriously. Security Assistant is designed within as a closed loop, meaning your questions and your data never leave our system. Your data is encrypted before, during, and after it has been analyzed (encryption in transit and at rest).
Similarly, your data is not accessible to others who do not have access to your organization. While we may use sanitized behavior patterns to better train the responses from Security Assistant, the specific details of your organization's compliance controls will not be used.
Security Assistant is currently restricted to users with Manager permissions. Someone in your organization may have attached evidence with sensitive information, and we do not want that to be unintentionally exposed to users without appropriate permissions. This restriction will remain in place until we have design a solution for restricting access to information by authorized user roles.
Tips
Attachments
Security Assistant performs best when reading text-based documents, like Policies or Procedures. It can also review images (like screenshots of your application settings) and structured data (like JSON or CSVs); however, it doesn't yet understand the structure of that data. We will be enriching Security Assistant with more context in coming releases, so expect the results to get better!
Sensitive evidence & attachments
If you have evidence that displays sensitive information, you can exclude those items from being reviewed by Security Assistant. To exclude evidence, open the evidence item's edit modal and toggle on the 'Mark evidence as sensitive' flag.
If this flag is enabled, Security Assistant will skip any attachments added to that evidence item when searching for answers to your questions.
False positives
We've designed Security Assistant to only return an answer when it is very confident that it will be correct, but, like all AI systems, it may sometimes return false information. If the response seems dubious, double check the source(s).
False negatives
Because we've set Security Assistant's confidence threshold to be so high, it may also say, "I don't know," but still return valid sources where the information is likely located. This will also improve in coming releases, but, in the meantime, don't hesitate to explore the returned sources because the answers to your questions have likely been located correctly.