<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://tangothreesix.github.io/feed.xml" rel="self" type="application/atom+xml" /><link href="https://tangothreesix.github.io/" rel="alternate" type="text/html" /><updated>2026-07-16T05:59:49+00:00</updated><id>https://tangothreesix.github.io/feed.xml</id><title type="html">// TANGO_THREE_SIX</title><subtitle>personal thoughts</subtitle><author><name>Jan</name></author><entry><title type="html">SOC Type II - Not a panacea</title><link href="https://tangothreesix.github.io/SOC2/" rel="alternate" type="text/html" title="SOC Type II - Not a panacea" /><published>2026-07-16T05:50:00+00:00</published><updated>2026-07-16T05:50:00+00:00</updated><id>https://tangothreesix.github.io/SOC2</id><content type="html" xml:base="https://tangothreesix.github.io/SOC2/"><![CDATA[<p>Went down a rabbit hole tonight to figure out what data privacy exists for all of the popular AI models folks are using these days. My search ended up focused on Anthropic and Claude - and during my research I ran across this Reddit post.</p>

<p>https://www.reddit.com/r/Anthropic/comments/1qxnr2b/comment/o3ys7ch/?utm_source=share&amp;utm_medium=web3x&amp;utm_name=web3xcss&amp;utm_term=1&amp;utm_content=share_button</p>

<p>Naturally, I had the urge to comment on the assertion that SOC Type II attestation means an employee can’t access your data without your permission.</p>

<p>One of the commonly known facts of tech companies that provide services, but rarely ever discussed with customers, is that customer data absolutely still is used. How else are companies expected to better train their models, heuristics, feature designs, etc. if they can’t see how their customers are using it and what they’re feeding to their services? But before you begin accusing me of not knowing what security framework attestations like SOC Type II look for to prove me wrong, I will point out a couple of facts.</p>

<ol>
  <li>Personally Identifiable Information (PII) can be obfuscated in order for customer data to be used.</li>
  <li>Controls to limit access to said customer data can absolutely exist to satisfy frameworks like SOC Type II, and those controls are NOT insignificant. Controls such as timed access, RBAC, employee actions being audited, background checks, periodic access reviews, and similar are expected as part of being able to pass attestation.</li>
</ol>

<p>More importantly, the two can be true at the same time. Engineers at helpdesk may have tightly-controlled access to data that is attributable to customers by PII, while product researchers and developers can still have access to obfuscated versions of that customer data where it can’t be attributed to anything meaningful - controlled and policy-driven access, but access without user knowledge nonetheless.</p>

<p>While I obviously can’t go into specifics, a previous employer was a perfect example of this, especially when it came to feeding security analysis and improving cybersecurity features.</p>

<p>Before any of the conspiracy theorist begin pointing to this as a smoking gun on how evil tech companies are, the context of this is also important. All tech companies collect user data. ALL. Apple certainly collects data on how their iPhones are used. ISPs provide data on the kind of traffic they see from their pipes. Microsoft certainly analyzes how their various products, such as Azure, Office, and Windows are used. AI companies such as Anthropic are simply following the same model - the only real distinction needed here is that this data is sanitized in a way to ensure cybersecurity framework compliance. Because, after all, if you can’t boast you’re compliant to NIST 800-171, FedRAMP, or ISO 27001, you and your services are nonstarters in the enterprise space, since no executive can recommend your products without the necessary cybersecurity air cover to protect them.</p>

<p>Something to think about. But the same saying holds true - if you’re not paying for the costs of running the services, then you are service. The customers are just different than you - usually ones that have an entry in the S&amp;P 500.</p>

<p>— Jan</p>]]></content><author><name>Jan</name></author><summary type="html"><![CDATA[Went down a rabbit hole tonight to figure out what data privacy exists for all of the popular AI models folks are using these days. My search ended up focused on Anthropic and Claude - and during my research I ran across this Reddit post.]]></summary></entry><entry><title type="html">A New Beginning. A New Hope</title><link href="https://tangothreesix.github.io/a-new-beginning/" rel="alternate" type="text/html" title="A New Beginning. A New Hope" /><published>2026-07-15T12:00:00+00:00</published><updated>2026-07-15T12:00:00+00:00</updated><id>https://tangothreesix.github.io/a-new-beginning</id><content type="html" xml:base="https://tangothreesix.github.io/a-new-beginning/"><![CDATA[<p>It has been almost 2 years to the day my divorce began.</p>

<p>Since then, I feel as if I’ve lived a whole lifetime of changes since. And continue to live them.</p>

<p>One of those changes will be to note down my thoughts, random as they are, here. Emotional, technical, spiritual, factual - everything that I can safely share publicly.</p>

<p>May this space be a space of value - not to you, but to me.</p>

<p>— Jan</p>]]></content><author><name>Jan</name></author><summary type="html"><![CDATA[It has been almost 2 years to the day my divorce began.]]></summary></entry></feed>