Skip to main content

Current Security Controls

Already Implemented

ControlImplementation
MFAAWS Cognito (optional per user)
Encryption at restRDS, EBS, S3
Encryption in transitTLS 1.2+ everywhere
Network segmentation3-VPC architecture
RBACOrganization and project roles
Security scanningCI/CD pipeline
Audit loggingPartial (user activity)
Least privilegeIAM roles per service

Evidence Locations

  • Terraform configs: statux-infra/environments/prod/
  • Auth guards: statux-api/libs/auth/
  • CI workflows: .github/workflows/security.yml