Security & Compliance Posture
SOC 2 / ISO 27001 Control Mapping (implemented)
| Control | Implementation |
|---|---|
| Access Control (AC) | SSO-free key-only SSH, root disabled on satellites, Vault-managed secrets, least-privilege policies |
| Encryption (SC) | TLS 1.2+ on public; tailnet-encrypted inter-node; Vault transit; provider-at-rest encryption |
| Audit (AU) | Tamper-evident hash-chained audit ledger; correlation IDs on every event |
| Monitoring (SI) | Telemetry scope-classification, suspicious scoring, expiry/CPU watchdogs, 11-check production gate |
| Backup (CP) | Plain .tar.gz (provider-encrypts at rest) + dual-IPFS + offsite; 4x/day; 30-day rolling |
| Incident (IR) | Self-heal restarts failed units; escalation to ai2 witness + owner |
| Supply Chain (SR) | Pinned deploy key, branch guard (cloud_os -> live_operations unidirectional) |
Certifications status
SOC 2 Type II and ISO 27001: roadmap — controls implemented; formal audit pending engagement. We operate to the standard today.