Skip to content

Security overview

Control summary

DomainControls
Encryption in transitTLS 1.2+ enforced everywhere (CloudFront minimum protocol, API Gateway, S3 TLS-only policies); HSTS with preload on all web origins
Encryption at restKMS customer-managed keys for documents (S3), metadata (DynamoDB), Lambda logs, and CloudTrail; key rotation enabled; S3-managed encryption for static assets
IdentityCognito user pools; strong password policy (12+ chars, complexity); optional MFA (TOTP); adaptive auth (risk-based challenges); PKCE OAuth with token revocation; preventUserExistenceErrors
AuthorizationAPI Gateway JWT authorizer + in-Lambda verification (defense in depth); per-document ownership checks on every mutation; least-privilege IAM per component
Edge protectionWAF (CloudFront + API Gateway): AWS managed common/bad-input/IP-reputation rule sets + IP rate limiting; security headers (CSP, frame-ancestors 'none', nosniff, referrer policy)
DetectionGuardDuty; CloudWatch alarms (5xx, latency, Lambda errors, DynamoDB throttles); CloudFront access logs; WAF metrics
Audit loggingMulti-region org CloudTrail with KMS-encrypted S3 + CloudWatch Logs; Lambda structured logging (no PII/token logging); S3 versioning as an audit trail for documents
Vulnerability managementConfig managed rules (encryption, public access, IAM, PITR); Security Hub standards (CIS + Foundational); dependency updates in CI; private vulnerability reporting (SECURITY.md)
AvailabilityServerless/usage-based; DynamoDB PITR; S3 versioning; multi-AZ by design (regional services); documented DR and backups
Data protectionLocal-first documents; owner-scoped storage keys; published copies strip owner identifiers; presigned URLs (10 min) for document bytes; no cross-tenant data paths

Secrets

No secrets in the repository. Deploy-time inputs (GitHub connection ARN, alert emails) are CDK context values. Any future secrets go to Secrets Manager with IAM-scoped access and rotation.

Reporting

See SECURITY.md in the repository for the private reporting process and 90-day disclosure policy.