Skip to main content

What golden-benchmark detection controls measure

Detection controls keyed to golden-dataset recall (such as cardholder-data detection) reflect the platform's measured benchmark accuracy, not your tenant's own traffic.

Prerequisites​

What these controls measure​

  1. Some detection controls (for example, cardholder-data detection) pass based on the platform's MEASURED recall against curated golden datasets, computed at release build time and embedded in the shipped software.
  2. A pass means the shipped classifier demonstrably detects that data class at or above the release threshold. It does not mean the control examined your tenant's own traffic.
  3. The same attested numbers apply to every tenant running that release: the control is a platform capability attestation, not a per-tenant traffic risk signal.

What to check for your own traffic​

  1. Per-tenant detection activity lives in Risk Signals and the session timeline: what was actually inspected, detected, and enforced in your environment.
  2. If a benchmark-keyed control passes but your Risk Signals show no detections, that usually means the relevant data class has not appeared in governed traffic — not that detection is broken.

Validate​

  • Benchmark-keyed controls identified in your framework view
  • Provenance understood: platform benchmark, not tenant traffic

Next steps​

  • Review the evidence-truth article for the full evidence-state model