TENANT_LIFECYCLE
BUILT + REFERENCE TESTED
Tenant creation, suspension, isolation and termination are explicit and fail closed.
PUBLIC SITE 80 · INSTITUTIONAL ENGINEERING
The source implements the control surface required to onboard an institution without re-architecting the platform: tenant isolation, OIDC/SAML binding contracts, SCIM lifecycle, customer key custody, service credentials, dual approval, governed data use, secure webhooks, tamper-evident audit, recovery evidence, incident kill-switching and a fail-closed customer-live truth gate.
Engineering admission
This is a seller-controlled source readiness decision, not external validation.
Control matrix
Every control is named so an evaluator can challenge it independently rather than relying on a generic enterprise-ready label.
BUILT + REFERENCE TESTED
Tenant creation, suspension, isolation and termination are explicit and fail closed.
BUILT + REFERENCE TESTED
Every tenant-bound object operation requires object-level tenant authorization.
BUILT + REFERENCE TESTED
Role and attribute constraints compose; cross-tenant access is denied.
BUILT + REFERENCE TESTED
High-risk changes support dual authorization by distinct principals.
BUILT + REFERENCE TESTED
OIDC issuer/audience/key/signature and freshness validation is implemented.
BUILT + REFERENCE TESTED
SAML metadata, entity, signing and audience requirements are modeled as a bindable institutional contract.
BUILT + REFERENCE TESTED
SCIM-style Users/Groups create, read, replace, patch, disable and delete semantics are implemented.
BUILT + REFERENCE TESTED
Privileged policy requires phishing-resistant MFA or institution-declared equivalent.
BUILT + REFERENCE TESTED
Service credentials are scoped, expiring, hash-only at rest, rotatable and revocable.
BUILT + REFERENCE TESTED
DPoP proof validation and replay rejection are implemented for high-risk API profiles.
BUILT + REFERENCE TESTED
Idempotency binds key to request fingerprint and rejects key reuse with a different request.
BUILT + REFERENCE TESTED
Tenant and principal request budgets fail closed without granting authorization.
BUILT + REFERENCE TESTED
Machine-readable API failures have stable problem types and request correlation.
BUILT + REFERENCE TESTED
Customer KMS/HSM, cloud KMS and seller-reference custody are distinct states.
BUILT + REFERENCE TESTED
Key version, allowed algorithms, rotation and deprecation are policy objects.
BUILT + REFERENCE TESTED
PQC migration readiness is explicit without claiming FIPS validation or deployment.
BUILT + REFERENCE TESTED
Data classification is mandatory for protected workloads.
BUILT + REFERENCE TESTED
Data use is bound to declared purpose and authorization.
BUILT + REFERENCE TESTED
Allowed regions are policy-bound and fail closed.
BUILT + REFERENCE TESTED
Retention and legal hold override deletion deterministically.
BUILT + REFERENCE TESTED
Cross-customer model training is denied by default.
BUILT + REFERENCE TESTED
Webhook payloads are secret-authenticated with timestamp and nonce binding.
BUILT + REFERENCE TESTED
Duplicate webhook nonce or stale timestamp is rejected.
BUILT + REFERENCE TESTED
Webhook targets reject loopback, link-local, private-IP and non-HTTPS destinations.
BUILT + REFERENCE TESTED
Retries have bounded exponential backoff and dead-letter state.
BUILT + REFERENCE TESTED
Security and consequential changes produce append-only hash-linked audit evidence.
BUILT + REFERENCE TESTED
Audit export is redacted, structured and SIEM/OpenTelemetry compatible.
BUILT + REFERENCE TESTED
Backups carry integrity manifests and reject tampered restore.
BUILT + REFERENCE TESTED
Recovery point and recovery time objectives are explicit policy objects.
BUILT + REFERENCE TESTED
Recovery drills produce attributable receipts; seller drills do not become customer evidence.
BUILT + REFERENCE TESTED
Incident state can suspend high-risk mutation while preserving read/audit access.
BUILT + REFERENCE TESTED
SBOM, source identity, build provenance and verification are required publication inputs.
BUILT + REFERENCE TESTED
Customer-live status requires externally signed activation evidence and cannot self-promote.
BUILT + REFERENCE TESTED
Seller evidence cannot mint E4/E5/E6, customer-live, certification or adoption.
Hostile boundary
The threat model is part of the engineering surface, including tenant-object authorization, replay, SSRF, raw-secret rejection, privilege separation, recovery failure and customer-live inflation.
TENANT_OBJECT_AUTHORIZATION
TENANT_BOUNDARY_DENIED
SENDER_CONSTRAINED_TOKENS
DPOP_REPLAY_OR_BINDING_DENIED
SEGREGATION_OF_DUTIES
SELF_OR_INCOMPLETE_APPROVAL_DENIED
SCIM_2_LIFECYCLE
INACTIVE_IDENTITY_REMOVED_FROM_ACTIVE_GROUP_USE
WEBHOOK_HMAC
SIGNATURE_OR_NONCE_REJECTED
WEBHOOK_SSRF_GUARD
PRIVATE_LOOPBACK_OR_NON_HTTPS_TARGET_DENIED
IDEMPOTENCY_FINGERPRINT
KEY_REUSE_WITH_DIFFERENT_REQUEST_DENIED
PURPOSE_LIMITATION
PURPOSE_OR_CROSS_CUSTOMER_USE_DENIED
RETENTION_LEGAL_HOLD
DELETE_DENIED_WHILE_HOLD_OR_RETENTION_ACTIVE
HASH_CHAINED_AUDIT
CHAIN_VERIFICATION_FAILS_ON_MUTATION
BACKUP_INTEGRITY
RECOVERY_READINESS_FAILS
INCIDENT_KILL_SWITCH
HIGH_RISK_MUTATION_HALTED
CUSTOMER_ACTIVATION_TRUTH_GATE
CUSTOMER_LIVE_FALSE_UNTIL_ALL_EXTERNAL_GATES_PASS
SECURE_BUILD_PROVENANCE
PUBLICATION_GATE_DENIED
Standards baseline
The engineering surface is mapped to current identity, OAuth, provisioning, API, telemetry and software-supply-chain references without claiming certification or conformance.
REFERENCE_MAPPING
digital identity proofing, authentication and federation baseline
REFERENCE_MAPPING
federation and assertions baseline
REFERENCE_MAPPING
OAuth 2.0 security BCP and sender-constrained-token preference
REFERENCE_IMPLEMENTATION
DPoP proof-of-possession profile
REFERENCE_IMPLEMENTATION
SCIM 2.0 user and group lifecycle model
REFERENCE_IMPLEMENTATION
machine-readable HTTP problem details
REFERENCE_MAPPING
HTTP message-signature interoperability reference
REFERENCE_MAPPING
trace, metric and log naming reference
REFERENCE_MAPPING
secure software development lifecycle reference
REFERENCE_MAPPING
build provenance and hardened build-level reference
REFERENCE_MAPPING
secure defaults, MFA, SSO and customer-accessible logging reference
REFERENCE_MAPPING
API authorization, authentication, resource-consumption and SSRF threat reference
REFERENCE_MAPPING
application security verification and procurement-control reference
REFERENCE_MAPPING
govern, identify, protect, detect, respond and recover cybersecurity-outcome reference
REFERENCE_MAPPING
agent transparency and control hook reference upstream of outcome closure