Security overview
Control summary
| Domain | Controls |
|---|---|
| Encryption in transit | TLS 1.2+ enforced everywhere (CloudFront minimum protocol, API Gateway, S3 TLS-only policies); HSTS with preload on all web origins |
| Encryption at rest | KMS customer-managed keys for documents (S3), metadata (DynamoDB), Lambda logs, and CloudTrail; key rotation enabled; S3-managed encryption for static assets |
| Identity | Cognito user pools; strong password policy (12+ chars, complexity); optional MFA (TOTP); adaptive auth (risk-based challenges); PKCE OAuth with token revocation; preventUserExistenceErrors |
| Authorization | API Gateway JWT authorizer + in-Lambda verification (defense in depth); per-document ownership checks on every mutation; least-privilege IAM per component |
| Edge protection | WAF (CloudFront + API Gateway): AWS managed common/bad-input/IP-reputation rule sets + IP rate limiting; security headers (CSP, frame-ancestors 'none', nosniff, referrer policy) |
| Detection | GuardDuty; CloudWatch alarms (5xx, latency, Lambda errors, DynamoDB throttles); CloudFront access logs; WAF metrics |
| Audit logging | Multi-region org CloudTrail with KMS-encrypted S3 + CloudWatch Logs; Lambda structured logging (no PII/token logging); S3 versioning as an audit trail for documents |
| Vulnerability management | Config managed rules (encryption, public access, IAM, PITR); Security Hub standards (CIS + Foundational); dependency updates in CI; private vulnerability reporting (SECURITY.md) |
| Availability | Serverless/usage-based; DynamoDB PITR; S3 versioning; multi-AZ by design (regional services); documented DR and backups |
| Data protection | Local-first documents; owner-scoped storage keys; published copies strip owner identifiers; presigned URLs (10 min) for document bytes; no cross-tenant data paths |
Secrets
No secrets in the repository. Deploy-time inputs (GitHub connection ARN, alert emails) are CDK context values. Any future secrets go to Secrets Manager with IAM-scoped access and rotation.
Reporting
See SECURITY.md in the repository for the private reporting process and
90-day disclosure policy.