> ## Documentation Index
> Fetch the complete documentation index at: https://docs.varios-ai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security-Relevant Settings

> Which settings affect the security of your data and how to install updates

The following settings change which data leaves VARIOS AI or who can access it. Review changes to them with particular care.

## Privacy and DLP

| Setting | Location | Effect | Recommendation |
| - | - | - | - |
| **GDPR Protection** per model | **Admin** > **Models** | **Disabled** sends content to the model without inspection. **Optional** leaves the decision to users. | **Enabled** or **Optional** for every external model |
| **DLP Entities** | **Settings** > **Privacy** | Deselected data types are no longer detected. | Keep all types active that occur in your data |
| **Allow List** | **Settings** > **Privacy** | Listed terms are never filtered. | Add only terms that never require protection |
| **Sensitivity Labels for Files** | **Settings** > **Privacy** | Classified files can be blocked. | Block confidential labels |
| **Allow OpenAI document processing** | **Settings** > **Privacy** | Documents are sent to the OpenAI API for processing. | Enable only if this transfer is permitted |
| **Permitted URL Protocols** | **Settings** > **Privacy** | Additional protocols are shown as clickable links in responses. | Add only protocols you need |

## Access and connectors

| Setting | Location | Effect | Recommendation |
| - | - | - | - |
| **Human-in-the-Loop** | **Admin** > **Connectors** | Without approval, the model runs connector calls on its own. | Enable for connectors that change or send data |
| Group permissions | **Admin** > **Groups** | Determine who may use models, assistants and connectors. | Grant as narrowly as possible |
| Authentication of MCP servers | **Admin** > **Connectors** > **MCP** | **No Authentication** connects servers without sign-in. | Only for public servers without access to your data |
| **API key expiry date** | **Admin** > **Credentials** | Without a date, you receive no reminder before expiry. | Set a date and renew keys regularly |
| **Enable support access** | **Settings** > **System information** | The VARIOS AI support team can view the settings and configuration of your instance. | Enable only for the duration of a support case |
| **Debug Mode** | **Settings** > **Privacy** | SuperAdmins see additional technical details about their own requests. | Enable only for troubleshooting |

## Network

| Setting | Location | Effect | Recommendation |
| - | - | - | - |
| **Proxy server address and port** | **Settings** > **General** | Outgoing connections run through your proxy server. | Enter the proxy only here, not as an environment variable of the containers |
| **Proxy exceptions** | **Settings** > **General** | Targets in the list are contacted directly. | Enter only internal targets |
| **Proxy Certificate (PEM format)** | **Settings** > **General** | VARIOS AI trusts connections that your proxy intercepts with this certificate. | Store only the certificate of your own proxy |
| Published ports | `docker-compose.yml` | Published ports bypass the host firewall. | Publish only 80 and 443, see [Security risks](./security-risks) |

## Install updates

VARIOS AI does not install updates automatically. You decide when an update is installed.

<Steps>
  <Step title="Get notified about new versions">
    Enable the **Update available** notification under **Settings** > **Notifications**.
  </Step>

  <Step title="Create a backup">
    Back up your installation as described under [Backup and Restore](../operations/backup).
  </Step>

  <Step title="Install the update">
    Under **Settings** > **System information**, select the new version at **Change version**, or follow the guide for the respective version in the **Operations** section.
  </Step>
</Steps>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.