Valeo · security governance / April 2026
How do you show real KPI logic without leaking confidential data?
I wanted to present the reporting model and its evolution as reusable professional work, but the underlying security data could not leave the client context. Anonymization therefore had to preserve the pattern without exposing the state.
Situation
A strong dashboard or audit timeline can be an excellent portfolio example, but actual control names, organizational units, counts and risk states may all be sensitive. Simply removing names is not enough when combinations of values and timing can still reveal more about the real environment than intended.
Approach
For the publishable version, I preserved the operating pattern rather than merely renaming entities: statuses, trend direction, decision points and reporting structure. Quantities and time relationships were changed so the original state could not be reconstructed, while the dashboard logic and the professional lesson remained representative.
Outcome
The resulting material could demonstrate how the governance system worked without publishing the client's actual security position. This later became a portfolio principle for enterprise work: show genuine engineering and governance patterns without turning internal client information into public evidence.