# Developer data-path pilot pack

Select one task, assign its control owners and record a scoped pilot decision.

Synthetic planning examples. No installed-product tests or results are included.

Source: https://aona.ai/solutions/ai-data-security-for-developers/
Sources checked: 2026-09-21

| Input source | Client/runtime | Recipient and retained copy to review |
| --- | --- | --- |
| Synthetic code | Selected editor or CLI | Model destination and transcript |
| Fake secret marker | Supported test input path | Control boundary before submission |
| Synthetic test trace | Paste or file upload | Provider request and retained history |
| Repository marker | Context or file-reading tool | Tool result and downstream context |

## Review checklist

- [ ] Define the task and environment
  Record the approved account, client/version, OS, execution location and repository owner.
- [ ] Give every input path an owner
  Separate client access, provider terms and supported endpoint policy evaluation.
- [ ] Keep planned and observed results separate
  Use untested until evidence exists; do not treat a marker as a realistic secret-detector test.

## Included example files

- README.md
- data-path-register.csv
- synthetic-pilot-markers.json
- pilot-decision.md

## Source references

- Cursor: Privacy and Data Governance: https://cursor.com/docs/enterprise/privacy-and-data-governance (2026-09-21)
- OpenAI: Agent approvals and security: https://learn.chatgpt.com/docs/agent-approvals-security (2026-09-21)
- Aona: AI security coverage: https://aona.ai/resources/ai-security-coverage/ (2026-09-21)

Use the worksheet within the relevant legal, contractual and technical scope. It is not a certification or a record of an installed-product test.
