Documentation index

Security Operations

Customer Security Boundary

The customer owns the host, network, PostgreSQL service, object or file storage, encryption keys, TLS private keys, identity administration, backups, monitoring, retention, and incident response for the on-premise deployment.

Required Controls

Identity and Access

Network and Transport

Secrets and Data

Logging and Monitoring

Patching and Vulnerability Management

External Processing

Customer evidence is processed locally by default. No customer data is sent to external AI services by default. Any optional external processing requires explicit customer configuration, approved contractual terms, documented data classification, and an approved data-flow boundary.

Incident Response

Document the customer incident owner, Project X IT support contact, severity path, evidence preservation process, key-rotation procedure, containment actions, notification requirements, and recovery approval. Never send raw customer evidence unless the customer authorizes a protected transfer.