The 6 Dust AI security checks Black Cat runs
Black Cat SSPM evaluates 6 security policies against your Dust AI configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect Dust AI — what access Black Cat needs, and why.
Data sharing & exposure (3)
- Open Space With Connected Data severity: high
- Sensitive Data Source In Open Space severity: high
Other checks (3)
severity: medium Member External Domain fix difficulty: easy #
Review workspace members whose email domain is outside the organization
- Open Members in Dust
- Confirm whether each external member should retain access
- Remove members who no longer require access
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: medium Agent Using Unapproved Model Provider fix difficulty: easy #
Reconfigure agents that use model providers outside the approved list
- Open the agent's model settings in Dust
- Switch to an approved model provider
Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low Shadow Tool Usage fix difficulty: medium #
Review tools used in the workspace that are outside the approved set
- Review the tool usage analytics in Dust
- Disable or govern unapproved tools at the workspace level
Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4