Reaches the portal
- Counts and trends: open alerts by severity and age, active cases, fleet coverage, data-source health, telemetry volume.
- Month-to-date and monthly SLA attainment.
- Published reports, as frozen copies.
- The curated summary of each case: title, category, state, dates, the customer-facing write-up.
- Ticket threads the customer is part of.
- The logo, note and support contact you set for the organization.
Stays in the console
- Raw events and search.
- Alert payloads, event graphs, process trees.
- Analyst notes, the war room, attachments not explicitly published.
- Analyst names; provenance is removed from published material.
- Detection rules, playbooks, suppressions, integrations, credentials.
- Anything from another organization.
The separation is enforced at the data access layer, beneath the portal's interface.