Security Posture
| Owner | Classification | Version | Effective | Next review | Status |
|---|---|---|---|---|---|
| Sekhar Prakash | Internal | 1.6 | 2026-06-24 | 2026-11-27 | Active |
Purpose. A live snapshot of the current security posture for the Finaisse platform (multi-tenant financial SaaS). Established at iteration 1 (2026-06-24); last re-verified 2026-09-10; reviewed quarterly and on major architecture change.
At a glance
| Environments | Target framework |
|---|---|
Staging on Railway (live) · Production on AWS ap-south-1 (in build) | SOC 2 (target) · India DPDP baseline · ISO 27001 likely |
Pre-production hardening in progress
- 0 of 20 domains at target state — 10 critical, 10 partial.
- 4 P0 findings block production go-live — down from 8: tenant binding (F-01), both SQL injections (F-03, F-39) and password hashing (F-40) were fixed and verified in the 2026-09-04 → 09-09 window.
- More findings = the posture working: dev security review surfaces real issues before the first production tenant.
- Latest pass + full history → Audit & Assessment Log · what's been assessed → Coverage.
Status by area
Each area's current status; drill into its detail page.
| Area | Status | Detail |
|---|---|---|
| Findings | 4 P0 · 12 P1 · 12 P2 · 5 P3 open · 7 resolved · 1 risk-accepted | Findings Register |
| Domain maturity | 0 🟢 · 11 🟠 · 9 🔴 (of 20) | Security Domains |
| Assessment coverage | 5 of 9 lenses run (owned by Coverage) | Coverage & Methodology |
| Controls & frameworks | SOC 2 Type II in prep · SOC 1 Type 2 required (STP) | Framework & Cert Register |
| Data & privacy | RoPA · data-flows · subprocessors — in progress | Data & Privacy |
| AI governance | Tokenisation designed · DPIA + no-train endpoint pending | AI Governance |
| Production go-live | 🔴 blocked — 4 P0 + detection baseline gaps | AWS Production Gate |
All findings carry the security label and sit on the Finboard project.
The 4 P0 blockers — must clear before production:
| Finding | Blocker |
|---|---|
| F-04 | Permissive CORS (origin: () => true + credentials), including admin apimgmt |
| F-25 | Mass-assignment — 39 Tier-1 routes + 2 approval writes with no trusted actor (runtime scan, 2026-09-23; Tier 2 split to F-54) |
| F-26 | Arbitrary-field filtering (BOLA) — surface moved, hole not closed |
| F-41 | No brute-force / lockout protection on signin |
Cleared in the 2026-09-04 → 09-09 window: F-01 tenant binding · F-03 and F-39 SQL injection · F-40 password hashing (now argon2id). See the Findings Register for the verified fix detail.
7 owner decisions pending — tooling, vendor & scope calls → Open Decisions.
Domain maturity — 20 domains
🔴 critical gaps · 🟠 partial · 🟢 healthy · 0 🟢 / 11 🟠 / 9 🔴 (D7 Tenant Isolation 🔴→🟠 — binding landed 2026-09-04; RLS backstop and the CI cross-tenant test remain. D18 Vendor Risk 🔴→🟠 2026-09-15 — the Subprocessor Register exists; DPAs/attestations still unrecorded)
Red domains (9): 1 Governance · 4 IAM · 5 AppSec · 6 API · 10 Container & Runtime · 15 Compliance · 16 Financial Data Integrity · 19 Endpoint · 20 People
The remaining 11 are 🟠. Per-domain scores and their rationale live in Security Domains — that page owns them; this one shows the tally. The full 20-row table used to be duplicated here, which meant every score change had to be made in two places and the two drifted.
Go-live gate
Production is gated on must-have controls plus the application P0s above.
| Gate | Status |
|---|---|
| App blockers (tenant isolation, RBAC, SQLi, CORS, MFA, auth hardening) | 🟠 improving — RBAC enforced (F-02 ✅), tenant binding (F-01 ✅), both SQLi (F-03, F-39 ✅), password hashing (F-40 ✅). 4 P0s remain: CORS (F-04), mass-assignment (F-25), BOLA filter (F-26), signin throttling (F-41). RLS backstop still outstanding |
| Detection baseline (CloudTrail, GuardDuty, Security Hub, VPC Flow Logs) | 🟠 partial — GuardDuty + Flow Logs in; CloudTrail + Security Hub still out |
| Edge (WAF, ALB + TLS, HTTPS-only) | 🟢 ALB + ACM TLS + 80→443 + WAF in (F-13 ✅) |
| IAM least-privilege + KMS CMKs | 🟠 partial — CMKs + Identity Center in; IAM wildcards remain |
| Independent validation (penetration test) | 🔴 not started |
Full gate: AWS Production Security Gate → · AWS-native options for the open Part B items: Options Assessment → · broader AWS service research: Service Reference →
Related
- → Findings Register · Security Domains · Audit & Assessment Log · AWS Production Gate · AWS Gate — Options Assessment · AWS Service Reference
- Engineering: Platform Operations · Architecture
Access & handling
Restricted to members of the finaisse-org GitHub organization (Cloudflare Access, GitHub org-membership policy) — the same audience that can read the private repos and issues, and for the same reason: both authorise on org membership. Internal-confidential: do not share findings, issue links, or screenshots outside Finaisse. Exploit detail lives in the linked issues, not on this site.
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | 2026-06-24 | Sekhar Prakash | Iteration-1 posture established (20 domains, initial findings). |
| 1.1 | 2026-07-10 | Sekhar Prakash | Re-verification against main; F-13 (ALB/TLS) resolved. |
| 1.2 | 2026-07-18 | Sekhar Prakash | F-36 resolved (lockfile guard); F-37 raised. |
| 1.3 | 2026-08-06 | Sekhar Prakash | F-02 (backend RBAC) resolved; F-38 raised. |
| 1.4 | 2026-08-26 | Sekhar Prakash | F-39–F-41 raised; P0 count 5→8. |
| 1.5 | 2026-08-27 | Sekhar Prakash | Restructured to the Scoreboard template (At a glance · Status summary · Domain maturity · Go-live gate). |
| 1.6 | 2026-09-10 | Sekhar Prakash | Reconciled to live issue state: P0 8→4 (F-01, F-03, F-39, F-40 verified fixed); counts, cards, blocker table and go-live gate updated; P3 tier reflected. |
Finaisse Internal — Confidential. Not for external distribution.