> For the complete documentation index, see [llms.txt](https://documentation.connexica.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://documentation.connexica.com/cxair-ai/security-and-governance.md).

# 11. Security and Governance

* **Data disclosure:** prompts, report context, uploaded images and tool results may be sent to the selected external provider. Apply your organisation's data-classification and provider agreements.
* **Least privilege:** grant only the CXAIR permissions and MCP credentials required for the user's role.
* **Secrets:** never include API keys, bearer tokens or passwords in prompts, report HTML or documentation examples.
* **Validation:** independently verify important calculations, filters and decisions.
* **Change control:** save or export important reports before substantial AI-assisted design changes.
* **Logging:** review CXAIR and provider logs according to retention and privacy policies; diagnostic bundles may contain sensitive information.
* **Provider controls:** understand each provider's retention, regional processing, model training and content-handling terms.
