← BLACKSWAN OS
Security Operations · IAM · Zero-Trust
Internal Readiness · Simulated
Centre Status

Security Operations, IAM & Zero-Trust Control Centre

Governs production security readiness for BLACKSWAN Capital Markets OS — Microsoft Entra OIDC posture, MFA & conditional access, RBAC/ABAC entitlements, privileged-access management, session/token controls, secrets & keys, WAF/API protection, SIEM/logging, vulnerability management, secure SDLC, and security incident response. Every control carries an owner, an evidence reference, and an explicit conservative posture: internal readiness only, not security certification, not regulatory approval, not authorization for external launch.

Security controls
10
5 Enforced · 3 Pending Test · 1 Conditional · 1 Exception
Zero-trust readiness
8 / 8
Eight zero-trust pillars mapped to readiness + evidence
Privileged access
6 / 7
Reviewed within cadence · 1 stale review open
Open exceptions
9
Tracked in exception register · CISO + risk-committee review
Security control state legend
Not Assessed Draft Configured Pending Test Enforced Conditional Approval Exception Granted Watch Degraded Incident Open Blocked Remediated Archived
Twelve security domains

Security Operations & IAM domains

Identity Provider Readiness
Entra OIDC drafted

Production target is Microsoft Entra OIDC. Staging uses simulated factors; Entra registration drafted, awaiting tenant admin sign-off.

MFA & Conditional Access
Policy drafted

MFA mandatory for all admin and evidence-pack-owner roles. Conditional access rules drafted by jurisdiction, device posture, and session age.

RBAC / ABAC Entitlements
Roles + attributes mapped

Roles for founder, admin, evidence owner, reviewer, observer, stakeholder-room recipient. ABAC attributes: jurisdiction, classification, MNPI scope.

Privileged Access / PAM
JIT & recording drafted

Just-in-time elevation, recorded sessions, dual approver for break-glass, time-boxed token issuance, no shared admin credentials.

Session & Token Controls
Active

Short-lived access tokens, refresh-token binding, sliding-session expiry, hard-cap re-auth, anti-replay, secure cookie flags.

Secrets & Key Management
KMS-backed

Cloud KMS for application keys, secret manager for service credentials, rotation cadence per class, zero plain-text secrets in repos.

WAF / API Protection
Rule pack drafted

Edge WAF for OWASP Top 10 + custom rule pack for stakeholder room endpoints, evidence-pack export, auth flow, file upload.

SIEM / Logging
Pipeline live

Centralised security log pipeline: auth events, admin actions, stakeholder-room access, evidence-pack read/write, anomaly triage.

Vulnerability Management
3 open · all P3 or below

Dependency scan, static analysis, secret scan, infra review on every release. P0/P1 block release; P2/P3 track to SLA.

Secure SDLC / Change Control
Release-gated

Every release gated by Approval & Sign-Off + Release Control. Security review for changes touching auth, RBAC, secrets, evidence flow.

Security Incident Response
Runbook live

Severity triage, paging, war-room, regulator notification trigger, board paging trigger, evidence preservation, post-incident review.

Security Evidence Pack
Pack assembled

Control inventory · access reviews · session/token logs · key rotation · WAF/SIEM samples · vuln status · incident timeline.

IAM control inventory

Identity, MFA, conditional access & admin controls

Control Owner State Evidence ref Last test Blocker Next action
Microsoft Entra OIDC registration CISO · Identity Lead Drafted SEC-EV-ENTRA-001 2026-05-12 Tenant admin sign-off on app registration scope Complete tenant registration & capture client/redirect URIs
MFA policy (admin + evidence-pack owner) CISO Policy drafted SEC-EV-MFA-002 2026-05-13 Entra readiness Enforce via Entra Conditional Access once tenant live
Conditional access (jurisdiction · device · session age) CISO · IT Ops Drafted SEC-EV-COND-003 2026-05-13 Device-posture signal source pending Pilot device-posture check in admin cohort
Founder / admin RBAC CISO · Programme Manager Enforced SEC-EV-RBAC-004 2026-05-14 None Quarterly access review next 2026-08-01
Evidence-pack owner roles Head of Evidence Enforced SEC-EV-EVOWN-005 2026-05-14 None Quarterly access review
Stakeholder room recipient roles Head of Stakeholder Rooms · CISO Enforced SEC-EV-ROOM-006 2026-05-15 None Per-room access review on every share
Break-glass account CISO · COO (dual) Conditional Approval SEC-EV-BREAK-007 2026-04-02 Quarterly break-glass test overdue (target 2026-05-02) Schedule break-glass drill; produce evidence + revoke
Access reviews (quarterly) CISO · Programme Manager Q2 review in progress SEC-EV-AXR-008 2026-05-15 1 stale assignment under triage Close stale assignment by 2026-05-22
Privileged session logging CISO · SRE Lead Enforced SEC-EV-PSL-009 2026-05-15 None Continue weekly review of high-risk action sample
Token expiry & refresh binding Identity Lead Enforced SEC-EV-TOK-010 2026-05-14 None Re-test on Entra cutover
Microsoft Entra OIDC Production Cutover Readiness

Production identity controls, staging-auth quarantine, cutover gate

Conservative posture: The Entra OIDC readiness layer is internal identity / production-cutover readiness posture only. It is not security certification, not regulatory approval, not legal advice, not audit opinion, not compliance certification, not regulator submission, not permission grant, not launch authorisation, not client acceptance, and not external-use authorisation. Real Microsoft Entra tenant configuration, Conditional Access enforcement, and security / compliance / go-live acceptance must be supplied outside the platform before any production cutover.
Controls assessed
9
Identity · MFA · RBAC · sessions · break-glass · SIEM · acceptance
Ready · pending tenant
2
Internally scoped · tenant binding pending
In review (amber)
4
Counsel / security challenge open
Blocked (red)
1
Missing owner / evidence / acceptance
Config missing
2
ENTRA_* env vars not supplied
Env keys missing
7
of 7 required ENTRA_* keys
Accepted · internal
0
CISO + Compliance + Founder pending
Cutover gate
HOLD · NO-GO
Until env supply + acceptance
Staging-auth quarantine

Staging founder-only factors (email + passphrase + static MFA) are internal rehearsal only. They are held in process memory, with no real tenant, no real directory, no real Conditional Access, and no real SIEM forwarding. They are not production identity and are not external-use authorised. Production code paths must refuse the staging factor set before cutover.

Control Owner State Approval state Approval authority Evidence ref Last reviewed Unlock criterion
Microsoft Entra OIDC app registration
ENTRA_TENANT_ID · ENTRA_CLIENT_ID · ENTRA_ISSUER · ENTRA_JWKS_URI · ENTRA_REDIRECT_URI
CISO · Identity Lead Config missing Pending tenant supply CISO · Founder Office SEC-EV-ENTRA-001 2026-05-18 Supply ENTRA_* env vars outside the platform; bind tenant.
Conditional Access + phishing-resistant MFA CISO In review Policy drafted · acceptance pending CISO + IT Ops SEC-EV-MFA-002 2026-05-17 Enable Conditional Access at tenant; capture sign-in log sample; retire staging static MFA from production path.
Role / permission mapping (RBAC + ABAC)
ENTRA_REQUIRED_GROUP_ID
Programme Manager · CISO Ready · pending tenant Mapping drafted · tenant binding pending Programme Manager + CISO SEC-EV-RBAC-004 2026-05-17 Supply ENTRA_REQUIRED_GROUP_ID; reconcile with User & Role Permissions matrix.
Session issue · token handling · refresh / revocation CISO · Platform In review Implementation drafted · evidence sample pending CISO + Platform Lead SEC-EV-SESSION-006 2026-05-16 Capture session issue / refresh / revoke evidence against real Entra tenant.
Break-glass / privileged admin access
ENTRA_BREAK_GLASS_OWNER
CISO Config missing Owner not yet named in env CISO + Founder Office SEC-EV-BREAK-GLASS-007 2026-05-15 Supply ENTRA_BREAK_GLASS_OWNER; confirm offline custody; drill dual-approver activation.
Staging-only auth quarantine Platform Lead · CISO Ready · pending tenant Quarantine label live in staging CISO + Platform Lead SEC-EV-ENTRA-STAGING-QUARANTINE-001 2026-05-19 Production build refuses the staging factor set; staging banner remains for internal rehearsal only.
Audit evidence · SIEM forwarding CISO · SOC In review Pipeline configured · evidence sample pending CISO + SOC Lead SEC-EV-SIEM-008 2026-05-17 Capture SIEM forwarding evidence against real tenant; verify failed / suspicious sign-in alerting.
Failed / suspicious sign-in evidence CISO · SOC In review Counters drafted · sample needed CISO + SOC Lead SEC-EV-AUTH-ANOMALY-009 2026-05-16 Capture end-to-end failed / suspicious sign-in evidence from Entra sign-in log; exercise in control test.
Security / compliance / go-live authority acceptance CISO · Compliance · Founder Office Blocked Not yet captured CISO + Compliance + Founder Office SEC-EV-CUTOVER-ACCEPT-010 2026-05-15 Counter-signed internal acceptance against real tenant config and staging quarantine evidence.

Read-only fixture is exposed via /api/entra-oidc-readiness; presence-only environment posture via /api/auth/posture. No secrets are returned from any endpoint. Authoritative cutover gate is rendered in the Final Production Launch Control Tower and a summary card is mirrored in the Completeness Command Centre.

Production Environment Variable & Secret Readiness Register

Required production configuration · presence · ownership · custody · rotation · evidence

Conservative posture: This register reports the presence, ownership, approval, custody/rotation, and evidence posture of required production runtime configuration. No secret values, tokens, private keys, passwords, client secrets, or connection strings ever appear in the UI, API, fixture, or commit. Staging / demo values do not count as production. Internal configuration readiness posture only — not security certification, not regulatory approval, not legal advice, not audit opinion, not compliance certification, not regulator submission, not permission grant, not launch authorisation, not client acceptance, not capital/liquidity adequacy, and not external-use authorisation.
Items assessed
23
Identity · signing · storage · SIEM · monitoring · edge · comms · DR · regulatory · authority
Required missing
22
Required production items not yet supplied
Required present
0
Supplied via env outside the platform
In review
0
Partial owner / evidence in flight
Approved · internal
1
Counter-sign captured · internal posture only
Rotation / custody pending
22
Required items missing custody / rotation evidence
Env keys missing
24
of 24 declared production env keys (names only · never values)
Launch gate
HOLD · NO-GO
Until presence + approval + custody/rotation evidence
Secrets handling

Secret values are never read, logged, persisted, or emitted by this register. The API at /api/production-config-readiness reports each declared environment variable as a presence boolean only; the value itself stays in the secret manager / runtime environment and never crosses the API or UI boundary. Required production items that lack presence, approval, custody, or rotation evidence keep the launch gate at HOLD · NO-GO.

Configuration item Group Owner Presence Approval Custody / rotation Evidence ref Last reviewed Launch impact
Microsoft Entra OIDC tenant binding
ENTRA_TENANT_ID
Microsoft Entra OIDC CISO · Identity Lead Missing Pending Tenant id non-secret · OIDC app + signing material in offline custody SEC-EV-ENTRA-001 2026-05-18 Holds production identity cutover at HOLD · NO-GO
Microsoft Entra OIDC client + redirect URI
ENTRA_CLIENT_ID · ENTRA_REDIRECT_URI
Microsoft Entra OIDC CISO · Identity Lead Missing Pending Public client · authorisation-code + PKCE · no client secret required SEC-EV-ENTRA-001 2026-05-18 Holds production identity cutover at HOLD · NO-GO
Microsoft Entra OIDC issuer + JWKS endpoint
ENTRA_ISSUER · ENTRA_JWKS_URI
Microsoft Entra OIDC CISO · Identity Lead Missing Pending JWKS rotation handled by Entra · cache TTL refresh SEC-EV-ENTRA-001 2026-05-18 Without trusted issuer + JWKS, OIDC id_tokens cannot be verified
Microsoft Entra group gate (RBAC/ABAC)
ENTRA_REQUIRED_GROUP_ID
Microsoft Entra OIDC Programme Manager · CISO Missing In review Quarterly access review with User & Role Permissions matrix SEC-EV-RBAC-004 2026-05-17 RBAC cannot be enforced for production sign-in without a required group claim
Break-glass / privileged admin custody
ENTRA_BREAK_GLASS_OWNER
Microsoft Entra OIDC CISO Missing Blocked Offline credential custody · dual-approver activation drill quarterly SEC-EV-BREAK-GLASS-007 2026-05-15 Break-glass owner must be named before cutover
Session signing secret
SESSION_SECRET
Session / token signing Platform Lead · CISO Missing Pending Rotated every 90 days via secret manager · previous version retained one cycle SEC-EV-SESSION-006 2026-05-16 Staging in-memory secret does not count as production
Internal token / signed-URL signing key reference
TOKEN_SIGNING_KEY_REF
Session / token signing Platform Lead · CISO Missing Pending HSM-backed key manager · ref-only at runtime · rotation every 180 days with overlap SEC-EV-SIGNING-KEY-011 2026-05-16 Holds any signed export / signed-URL flow at HOLD · NO-GO
Evidence pack / controlled bundle export bucket
EVIDENCE_EXPORT_BUCKET
Evidence export storage Platform Lead · CISO Missing Pending KMS-encrypted · WORM/object-lock retention · signed-URL TTL ≤ 15 min EVID-EXPORT-BUCKET-001 2026-05-17 Local-disk staging export does not count as production
Evidence pack signed-URL signing secret reference
EVIDENCE_EXPORT_SIGNING_SECRET_REF
Evidence export storage Platform Lead · CISO Missing Pending Secret reference only · rotated every 90 days · tied to share-link audit trail EVID-EXPORT-SIGN-002 2026-05-17 External-use bundle release at HOLD · NO-GO until signing custody captured
SIEM forwarder endpoint
SIEM_FORWARDER_ENDPOINT
SIEM / audit forwarding CISO · SOC Missing In review Endpoint host recorded · forwarder credential rotated every 180 days SEC-EV-SIEM-008 2026-05-17 Audit + sign-in evidence cannot be relied upon without forwarding
SIEM forwarder credential reference
SIEM_FORWARDER_TOKEN_REF
SIEM / audit forwarding CISO · SOC Missing Pending Reference only · rotated every 180 days · outage runbook captured SEC-EV-SIEM-008 2026-05-17 Forwarder cannot be enabled in production without token reference
Observability / monitoring endpoint
MONITORING_ENDPOINT
Monitoring / alerting Platform Lead · SRE Missing In review Endpoint host recorded · ingest credential in secret manager OPS-MONITOR-001 2026-05-17 Production runtime cannot evidence health / latency / error budgets
On-call alert route reference
ALERT_ON_CALL_ROUTE_REF
Monitoring / alerting Platform Lead · SRE Missing Pending Route reference only · webhook secret in secret manager · rotated annually OPS-MONITOR-002 2026-05-17 Paging route must be captured and drilled before launch
WAF · security edge policy reference
WAF_POLICY_REF
WAF / security edge Platform Lead · CISO Missing In review Policy ref recorded · rule set reviewed monthly · OWASP top-10 + custom SEC-EV-WAF-001 2026-05-17 WAF rule set must be bound to production hostnames
TLS certificate / mTLS custody reference
TLS_CERTIFICATE_REF
WAF / security edge Platform Lead Missing Pending Certificate body + private key not exposed · ACM/Key Vault · auto-renew monitored SEC-EV-TLS-002 2026-05-17 Certificate custody and renewal monitor required before cutover
Transactional email / notification provider
NOTIFICATION_PROVIDER_REF
Email / notification Platform Lead · Comms Missing Pending API key in secret manager · rotated every 180 days · sender domain SPF/DKIM/DMARC COMMS-PROV-001 2026-05-16 Stakeholder-room notifications cannot land in production
Sender domain authentication (SPF · DKIM · DMARC)
NOTIFICATION_SENDER_DOMAIN
Email / notification Platform Lead · Comms Missing In review DNS records reviewed quarterly · DMARC at quarantine pending acceptance to reject COMMS-PROV-002 2026-05-16 External-use bundle release at HOLD · NO-GO until domain auth captured
Production backup vault (immutable / WORM)
BACKUP_VAULT_REF
Backup / DR Platform Lead · SRE Missing Pending Credential in secret manager · WORM retention · cross-region replica DR-VAULT-001 2026-05-17 Backup vault and restore drill required before launch
Disaster recovery restore drill evidence
DR_RESTORE_DRILL_REF
Backup / DR Platform Lead · SRE · COO Missing In review Drill cadence quarterly · evidence pack per drill DR-DRILL-002 2026-05-16 At least one production-bound restore drill required before launch
Regulatory source manifest (rule text · evidence trail)
REGULATORY_SOURCE_MANIFEST_REF
Regulatory data / source Regulatory Affairs · Legal Missing In review Reviewed monthly with Regulatory Change horizon · source provenance tracked REG-SOURCE-001 2026-05-15 Source manifest must be bound and reviewed before launch
Partner data feed binding (custodian / paying agent / partner routes)
PARTNER_DATA_FEED_REF
Regulatory data / source Operations · Partner Risk Missing Pending Reference only · partner credentials in secret manager · rotated per partner SLA PARTNER-FEED-001 2026-05-15 Partner-routed evidence at HOLD · NO-GO without feed binding
Production launch authority acceptance custody
LAUNCH_AUTHORITY_ACCEPTANCE_REF
Production launch authority Founder Office · CISO · Compliance · CFO Missing Blocked Acceptance language version-controlled · renewed at every material readiness change LAUNCH-AUTH-001 2026-05-15 Final internal acceptance is the last gate before any cutover (not external authorisation)
Staging-only auth quarantine label
STAGING_QUARANTINE_LABEL
Production launch authority Platform Lead · CISO Not applicable (staging only) Approved · internal Static label held in staging only · refused by any production code path SEC-EV-ENTRA-STAGING-QUARANTINE-001 2026-05-19 Not applicable to production runtime — recorded so register stays complete

Read-only fixture is exposed via /api/production-config-readiness; no secret values cross the API or UI boundary. Cross-references the Microsoft Entra OIDC Production Cutover Readiness layer (also at /api/entra-oidc-readiness) and the /api/auth/posture endpoint. Authoritative cutover gate is rendered in the Final Production Launch Control Tower and a summary card is mirrored in the Completeness Command Centre.

Production Hostname, DNS, WAF & Partner-Route Readiness Register

Ingress · edge · mTLS · partner-route controls · presence · approval · route exposure · evidence

Endpoint-safety rule: No real production hostname, DNS zone, WAF rule body, mTLS certificate body / private key, partner API endpoint, partner credential, token, or client secret appears in this register, in the API at /api/production-ingress-route-readiness, in the fixture, or in any commit. Only ownership, declared (non-secret) env-key NAMES, presence flags, approval state, route exposure state, evidence references, and unlock criteria are recorded. The staging hostname does not count as a production endpoint. Internal ingress / partner-route readiness posture only — not security certification, not regulatory approval, not legal advice, not audit opinion, not compliance certification, not regulator submission, not permission grant, not launch authorisation, not client acceptance, not capital/liquidity adequacy, not external endpoint authorisation, and not external-use authorisation.
Controls assessed
20
Hostname · DNS · TLS · WAF · CDN · gateway · mTLS · partner · rate-limit · monitoring · rollback · authority
Internal-ready
0
Owner + approval + monitoring + rollback evidence captured
In review
3
Owner / approval / monitoring in flight
Blocked / missing
15
Required controls not captured · holds launch at HOLD · NO-GO
Restricted review
1
Counsel / partner-routed review only · no external exposure
External-route blocked
16
Routes externally blocked at WAF / API gateway / DNS
Route monitoring pending
2
Per-route telemetry / SIEM forwarding not yet bound
Production launch
HOLD · NO-GO
Until presence + approval + monitoring + rollback + authority
Endpoint-safety handling

Production hostnames, DNS zones, WAF rule bodies, mTLS certificate bodies / private keys, partner API endpoints, partner credentials, tokens, and client secrets are never exposed in this register, the API, the fixture, or any commit. The API at /api/production-ingress-route-readiness reports only ownership, declared (non-secret) env-key NAMES, per-key presence booleans, approval state, route exposure state, evidence references, and unlock criteria. Until DNS ownership, TLS / WAF, API gateway, mTLS / partner controls, rate-limit / abuse controls, route-level monitoring + audit forwarding, rollback / failover, and the internal external-route go-live authority are present and approved, every external-facing route stays externally blocked at WAF / API gateway / DNS and launch remains HOLD · NO-GO.

Control Group Owner State Approval Route exposure Evidence Last reviewed Launch impact
Production hostname registration & ownership proof
PRODUCTION_HOSTNAME_OWNERSHIP_REF
Hostname & DNSPlatform Lead · CISOMissingPendingExternal-blockedING-DNS-0012026-05-19Holds production launch at HOLD · NO-GO until ownership proven
Production DNS zone custody & DNSSEC / CAA posture
PRODUCTION_DNS_ZONE_REF
Hostname & DNSPlatform Lead · SREMissingIn reviewExternal-blockedING-DNS-0022026-05-18DNS zone custody must be captured before TLS / WAF binding
Production TLS certificate issuance custody
PRODUCTION_TLS_CERT_CUSTODY_REF
TLS lifecyclePlatform Lead · CISOMissingPendingExternal-blockedING-TLS-0012026-05-18TLS custody required before any hostname can be served
TLS certificate renewal & expiry monitor
TLS_RENEWAL_MONITOR_REF
TLS lifecyclePlatform Lead · SREMissingPendingExternal-blockedING-TLS-0022026-05-18Without monitor, cert expiry would silently break ingress
WAF policy bound to production hostnames
PRODUCTION_WAF_BINDING_REF
WAF · security edgePlatform Lead · CISOMissingIn reviewExternal-blockedING-WAF-0012026-05-19WAF must be bound to production hostnames before external traffic
Bot / credential-stuffing / abuse mitigation
BOT_ABUSE_RULESET_REF
WAF · security edgePlatform Lead · CISOIn reviewIn reviewExternal-blockedING-WAF-0022026-05-17Sign-in and partner callback routes must resist credential stuffing
CDN / edge routing binding
PRODUCTION_CDN_BINDING_REF
CDN · edge routingPlatform Lead · SREMissingPendingExternal-blockedING-CDN-0012026-05-18Origins must be shielded behind CDN with cache + signed-URL hygiene
API gateway / ingress controller binding
PRODUCTION_API_GATEWAY_REF
API gateway / ingressPlatform LeadMissingPendingExternal-blockedING-GW-0012026-05-18All production routes must traverse the API gateway / ingress
Route-level authentication via Entra OIDC
PRODUCTION_API_AUTH_BINDING_REF
API gateway / ingressCISO · Identity LeadBlockedBlockedExternal-blockedING-GW-0022026-05-18Routes cannot be authenticated until Entra OIDC tenant supplied
mTLS / partner certificate issuance & custody
PARTNER_MTLS_CUSTODY_REF
mTLS · partner custodyPlatform Lead · CISO · Partner RiskMissingPendingRestricted-reviewING-MTLS-0012026-05-17No partner route may go live without mTLS custody + drill
mTLS / partner certificate rotation & revocation drill
PARTNER_MTLS_ROTATION_REF
mTLS · partner custodyPlatform Lead · Partner RiskMissingPendingRestricted-reviewING-MTLS-0022026-05-17Rotation + revocation must be drilled per partner
Partner-route allowlist & contract scope
PARTNER_ROUTE_ALLOWLIST_REF
Partner allowlistOperations · Partner Risk · LegalRestricted reviewIn reviewRestricted-reviewING-PART-0012026-05-15Partner routes need contract scope + counsel countersign
Partner callback / webhook signature & replay protection
PARTNER_CALLBACK_SIGNATURE_POLICY_REF
Partner callbackPlatform Lead · Partner RiskMissingPendingExternal-blockedING-PART-0022026-05-16Inbound callbacks must enforce signature + replay protection
Rate-limit policy & burst caps
PRODUCTION_RATELIMIT_POLICY_REF
Rate limit · abusePlatform Lead · SREIn reviewIn reviewExternal-blockedING-RATE-0012026-05-17Required to resist credential-stuffing & abuse
Abuse-event runbook & containment
ABUSE_EVENT_RUNBOOK_REF
Rate limit · abusePlatform Lead · CISO · SOCMissingPendingExternal-blockedING-RATE-0022026-05-15Abuse events need containment + escalation path
Route-level monitoring & telemetry forwarding
ROUTE_MONITORING_BINDING_REF
Route monitoringPlatform Lead · SREIn reviewIn reviewExternal-blockedING-MON-0012026-05-18Per-route telemetry must reach monitoring + SIEM stack
Route-level audit log forwarding
ROUTE_AUDIT_FORWARDING_REF
Route monitoringCISO · SOCMissingPendingExternal-blockedING-MON-0022026-05-17Sign-in, partner-route, admin events must be SIEM-forwarded
Production rollback / failover route drill
ROLLBACK_FAILOVER_DRILL_REF
Rollback · failoverPlatform Lead · SRE · COOMissingIn reviewExternal-blockedING-ROLL-0012026-05-16External go-live needs a drilled rollback + failover path
External-route go-live authority custody
EXTERNAL_ROUTE_AUTHORITY_REF
External-route authorityFounder Office · CISO · Compliance · CFOBlockedBlockedExternal-blockedING-AUTH-0012026-05-15Final internal acceptance — not external endpoint authorisation
Staging URL quarantine label
(no env key — staging-only)
External-route authorityPlatform Lead · CISONot applicable (staging only)Approved · internalInternal-onlyING-STAGING-QUARANTINE-0012026-05-19Staging URL is never promoted to production endpoint

Read-only fixture exposed via /api/production-ingress-route-readiness; presence flags + non-secret env-key NAMES only. Cross-references the Production Environment Variable & Secret Readiness Register, the Microsoft Entra OIDC Production Cutover Readiness layer, /api/production-config-readiness, /api/entra-oidc-readiness, and /api/auth/posture. Mirrored summary in the Integration · API · Data Exchange Centre, the Final Production Launch Control Tower, the Production Monitoring Centre, and the Completeness Command Centre. Internal ingress / partner-route readiness posture only — not external endpoint authorisation, not regulator approval, not external-use authorisation. The staging hostname does not count as a production endpoint.

Secret Rotation, Key Custody & Recovery Drill Evidence Loop

Secret & key custody · custodian · rotation cadence · last rotation · next rotation due · recovery drill · evidence

Secrets rule: No secret value, certificate private key, encryption key, password, client secret, token, connection string, backup key, signing material, mTLS private key, break-glass credential, or recovery code appears in this register, in the API at /api/secret-rotation-key-custody, in the fixture, or in any commit. Only ownership, custodian, custody model, declared (non-secret) reference NAMES, presence flags, approval state, rotation cadence, last-rotation evidence date, next rotation due, recovery drill status / date, evidence references, and unlock criteria are recorded. Staging or demo credentials do not count as production secret custody evidence. Internal key-custody readiness posture only — not security certification, not regulatory approval, not legal advice, not audit opinion, not compliance certification, not regulator submission, not permission grant, not launch authorisation, not client acceptance, not capital/liquidity adequacy, not external endpoint authorisation, and not external-use authorisation.
Items assessed
15
Session · token · OIDC · storage · SIEM · monitoring · TLS · mTLS · backup · DB · break-glass · CI/CD · regulatory
Ready · internal
0
Owner + custodian + approval + rotation + recovery captured
In review
0
Owner / custodian / evidence in flight
Missing / blocked
13
Required custody / rotation / drill evidence not captured
Rotation overdue
0
Next-rotation due date elapsed without captured evidence
Recovery untested
13
Required restore / revocation drill not within freshness window
Custody approval pending
13
Required items lacking captured internal custody approval
Production launch
HOLD · NO-GO
Until custody + rotation evidence + recovery drill captured
Secrets & key custody handling

Secret values, certificate private keys, encryption keys, passwords, client secrets, tokens, connection strings, backup keys, signing material, mTLS private keys, break-glass credentials, and recovery codes are never exposed in this register, the API, the fixture, or any commit. The API at /api/secret-rotation-key-custody reports only ownership, custodian, custody model, declared (non-secret) reference NAMES, per-key presence booleans, approval state, rotation cadence, last-rotation evidence date, next rotation due, recovery drill status / date, evidence references, and unlock criteria. Until session signing, JWT/OIDC signing, Entra OIDC app credential, evidence export storage credential, SIEM forwarding token, monitoring webhook secret, TLS private-key custody, mTLS partner-key custody, backup encryption key, data-store encryption key, break-glass credential, CI/CD deploy token, and regulatory data API credential custody are captured with rotation cadence + last-rotation evidence + next rotation due + recovery drill evidence, launch remains HOLD · NO-GO and external-use bundle release is blocked.

Item Group Owner / custodian Custody model State Approval Rotation cadence Last rotation Next rotation due Recovery drill Evidence Launch impact
Session signing secret
SESSION_SIGNING_SECRET
Session · token signingCISO · Identity Lead / CISO · Platform LeadSecret-manager-backedMissingPending90 days——Required · not drilledSEC-EV-ROT-001Holds HOLD · NO-GO until rotation + recovery drill captured
JWT / OIDC signing key
JWT_SIGNING_KEY_REF
Session · token signingCISO · Identity Lead / Platform LeadKMS-backedMissingPending180 days——Required · not drilledSEC-EV-ROT-002Holds external-facing OIDC trust at HOLD · NO-GO
Entra OIDC app secret / cert credential
ENTRA_APP_CREDENTIAL_CUSTODY_REF
Entra OIDC credentialCISO · Identity Lead / Identity Lead · Platform LeadSecret-manager-backedMissingPending90 days——Required · not drilledSEC-EV-ROT-101Holds production identity cutover at HOLD · NO-GO
Entra OIDC federated cert credential
ENTRA_FEDERATED_CERT_CUSTODY_REF
Entra OIDC credentialCISO · Identity Lead / Identity Lead · Platform LeadKMS-backedNot applicablePending365 days——OptionalSEC-EV-ROT-102Optional path; only applies if federated cert credential selected
Evidence export storage credential
EVIDENCE_EXPORT_STORAGE_KEY_REF
Evidence export storageHead of Evidence · CISO / Platform LeadSecret-manager-backedMissingPending90 days——Required · quarterly restore drillSEC-EV-ROT-201Holds external-use bundle release at HOLD · NO-GO
SIEM / audit forwarding token
SIEM_AUDIT_FORWARDING_TOKEN_REF
SIEM forwardingCISO · SOC Lead / Platform Lead · SOCSecret-manager-backedMissingPending90 days——Required · annual restore drillSEC-EV-ROT-301Audit forwarding must be live before any external-use
Monitoring / alerting webhook secret
MONITORING_ALERTING_WEBHOOK_SECRET_REF
Monitoring · alertingSRE Lead · CISO / Platform LeadSecret-manager-backedMissingPending180 days——Required · paging drillSEC-EV-ROT-401Alerting must be live before external-use bundle release
Production TLS private-key custody
PRODUCTION_TLS_PRIVATE_KEY_CUSTODY_REF
TLS custodyPlatform Lead · CISO / Platform LeadHSM-backedMissingPending90 days——Required · annual revocation drillSEC-EV-ROT-501No production hostname may be served without TLS private-key custody
mTLS partner private-key custody
PARTNER_MTLS_PRIVATE_KEY_CUSTODY_REF
mTLS partner custodyPlatform Lead · CISO · Partner Risk / Platform LeadHSM-backedMissingPending180 days——Required · per-partner revocation drillSEC-EV-ROT-601No partner route may go live without mTLS partner key custody
Backup vault encryption key
BACKUP_ENCRYPTION_KEY_CUSTODY_REF
Backup · DRPlatform Lead · CISO · COO / Platform Lead · COOHSM-backedMissingPending365 days——Required · quarterly restore drillSEC-EV-ROT-701External-use requires evidenced backup / restore drill
Data-store encryption key
DATASTORE_ENCRYPTION_KEY_CUSTODY_REF
Data-store custodyPlatform Lead · CISO / Platform LeadKMS-backedMissingPending365 days——Required · annual rotation drillSEC-EV-ROT-801External-use requires evidenced data-store encryption custody
Break-glass credential custody
BREAK_GLASS_CREDENTIAL_CUSTODY_REF
Break-glassFounder Office · CISO · Board Secretariat / Board Secretariat · CISO (dual control)Offline custodyMissingPending365 days (envelope refresh)——Required · quarterly retrieval drillSEC-EV-ROT-901External-use requires evidenced break-glass posture
CI/CD deploy token custody
CI_CD_DEPLOY_TOKEN_CUSTODY_REF
CI/CD pipelinePlatform Lead · CISO / Platform LeadSecret-manager-backedMissingPending90 days——Required · per rotationSEC-EV-ROT-A01External-use requires evidenced deploy token custody
Regulatory data feed / partner API key
REGULATORY_DATA_API_KEY_CUSTODY_REF
Regulatory data feedRegulatory Affairs · Platform Lead / Platform Lead · Partner RiskSecret-manager-backedMissingPending180 days——Required · per rotationSEC-EV-ROT-B01External-use requires evidenced partner API key custody
Staging founder MFA factor quarantine
(no production reference — staging-only)
Session · token signingPlatform Lead · CISO / Platform Lead · CISONot applicableNot applicable (staging only)Approved · internalQuarantined——Not applicableSEC-EV-ROT-STAGING-001Staging factor is never promoted to production secret custody

Read-only fixture exposed via /api/secret-rotation-key-custody; reference NAMES, presence flags, custody owner, custodian, custody model, approval state, rotation cadence, last-rotation evidence date, next rotation due, recovery drill status / date, and evidence references only. Cross-references the Production Environment Variable & Secret Readiness Register, the Production Hostname, DNS, WAF & Partner-Route Readiness Register, the Microsoft Entra OIDC Production Cutover Readiness layer, /api/production-config-readiness, /api/production-ingress-route-readiness, /api/entra-oidc-readiness, and /api/auth/posture. Mirrored summary in the Final Production Launch Control Tower, the Operational Runbooks & Day-2 Support Centre, the Data Governance & Retention Centre, and the Completeness Command Centre. Internal key-custody readiness posture only — not security certification, not regulatory approval, not legal advice, not audit opinion, not compliance certification, not regulator submission, not permission grant, not launch authorisation, not client acceptance, not external endpoint authorisation, and not external-use authorisation. Staging or demo credentials do not count as production secret custody evidence.

Production Backup, Restore & Data Recovery Evidence Centre

Backup scope · restore drills · RPO/RTO · retention · DR · recovery authority

Backup & recovery rule: No backup vault credential, storage account key, database credential, encryption key material, recovery code, signed-URL secret, private endpoint, production data row, or live production dataset appears in this register, in the API at /api/backup-restore-recovery-evidence, in the fixture, or in any commit. Only ownership, custodian, custody model, declared (non-secret) reference NAMES, presence flags, approval state, backup cadence, last-backup evidence date, last restore drill date, RPO/RTO targets, measured RPO/RTO, retention / legal-hold posture, evidence references, and unlock criteria are recorded. Staging or demo backups do not count as production recovery evidence. Internal backup/recovery readiness posture only — not security certification, not regulatory approval, not legal advice, not audit opinion, not compliance certification, not regulator submission, not permission grant, not launch authorisation, not client acceptance, not capital/liquidity adequacy, not external endpoint authorisation, and not external-use authorisation.
Controls assessed
15
Schedule · scope · encryption · restore · RPO/RTO · WORM · evidence · audit · DB · IaC · runbook · DR · monitoring · retention · authority
Ready · internal
0
Owner + approval + cadence + last backup + restore drill + RPO/RTO + retention captured
Recovery untested
15
Restore drill / DR exercise not within freshness window
RPO/RTO unverified
8
Targets declared · measurement not captured against drill
Retention unverified
15
Retention lock + legal-hold alignment not evidenced end-to-end
Approval pending
15
Required items lacking recovery authority counter-sign
Missing / blocked
10
Required backup / restore / retention evidence not captured
Production launch
HOLD · NO-GO
Until backup scope + restore drill + RPO/RTO + retention + authority captured
Control Group Owner / custodian Custody model State Approval Backup cadence Last backup Last restore drill RPO target RTO target Retention / legal hold Evidence Launch impact
Database backup schedule & automation
BACKUP_CADENCE_DATABASE_REF
Backup schedulePlatform Lead / Platform Lead · CISOVault-backedMissingPendingContinuous PITR + daily full——15 min4 hrPer jurisdictional retention matrixBKP-EV-SCH-001Holds HOLD · NO-GO until cadence + last backup + restore drill + RPO/RTO captured
Production backup scope inventory
BACKUP_SCOPE_INVENTORY_REF
Scope inventoryPlatform Lead / Platform Lead · Head of Evidencen/a — inventoryMissingPendingReviewed quarterly——n/an/aLifetime of production systemBKP-EV-SCP-001Holds HOLD · NO-GO until backup scope approved + cross-linked
Backup encryption key custody link
BACKUP_ENCRYPTION_KEY_REF
Encryption / custodyCISO / CISO · Platform LeadKMS-backedMissingPendingPer Secret Rotation Loop——n/an/aPer backup retention policyBKP-EV-ENC-001Holds HOLD · NO-GO until KMS/HSM-backed backup key custody + rotation + drill captured
Database restore drill evidence
RESTORE_DRILL_DATABASE_REF
Restore drillPlatform Lead / Platform Lead · CISOVault-backedRecovery untestedPendingQuarterly restore drill——15 min4 hrPer database backup retentionBKP-EV-RST-001Holds HOLD · NO-GO until production-grade restore drill captured with measured RPO/RTO
Database RPO · RTO targets & measurement
RPO_RTO_DATABASE_REF
RPO/RTO targetsPlatform Lead / Platform Lead · CISOn/a — targetRPO/RTO unverifiedPendingMeasured every drill——15 min4 hrn/aBKP-EV-RPO-001Holds HOLD · NO-GO until measured RPO/RTO inside target captured
Immutable backup · retention lock · WORM
IMMUTABLE_RETENTION_LOCK_REF
Retention lockCISO / CISO · Platform LeadImmutable object storageRetention unverifiedPendingLock state verified quarterly——n/an/aPer jurisdictional retention + legal-hold matrixBKP-EV-IMM-001Holds HOLD · NO-GO until WORM / object-lock retention evidenced end-to-end
Evidence pack & controlled-bundle recovery
EVIDENCE_EXPORT_RECOVERY_REF
Evidence exportHead of Evidence · CISO / Platform LeadImmutable object storageMissingPendingPer-pack on create + daily snapshot——1 hr8 hrMin 7 years (legal hold)BKP-EV-EXP-001Holds external-use bundle release at HOLD · NO-GO until evidence pack backup + restore + retention captured
Audit log · SIEM backup & recovery
AUDIT_LOG_RECOVERY_REF
Audit log recoveryCISO / CISO · SRE LeadVault-backedMissingPendingContinuous forwarder + daily snapshot——5 min2 hrPer regulator-required audit retentionBKP-EV-AUD-001Holds HOLD · NO-GO until audit log backup + retention + restore drill captured
Database · data-store point-in-time recovery
DATASTORE_PITR_REF
Data-store recoveryPlatform Lead / Platform LeadVault-backedMissingPendingContinuous PITR window——15 min4 hrPer data class retentionBKP-EV-PITR-001Holds HOLD · NO-GO until PITR + restore drill + measured RPO/RTO
Configuration · runtime · IaC recovery
CONFIGURATION_IAC_RECOVERY_REF
Config / IaC recoveryPlatform Lead / Platform LeadVault-backedMissingPendingPer IaC commit + daily snapshot——1 hr4 hrSource control retentionBKP-EV-CFG-001Holds HOLD · NO-GO until IaC / runtime image rebuild evidenced
Incident recovery runbook · per data class
INCIDENT_RECOVERY_RUNBOOK_REF
Incident runbookSRE Lead · CISO / SRE Leadn/a — runbookMissingPendingReviewed quarterly——n/an/aLifetime of production systemBKP-EV-RUN-001Holds HOLD · NO-GO until incident recovery runbook approved + drilled
DR · region-failover exercise
DR_FAILOVER_EXERCISE_REF
DR / failoverCISO / Platform Lead · SRE LeadVault-backedRecovery untestedPendingAnnual DR + semi-annual tabletop——1 hr8 hrLifetime of production systemBKP-EV-DR-001Holds HOLD · NO-GO until full DR / region-failover exercise executed
Backup monitoring · alerting · escalation
BACKUP_MONITORING_REF
Monitoring / alertingSRE Lead / SRE Lead · Platform Leadn/a — monitoringMissingPendingContinuous monitoring + on-failure paging——n/an/aPer audit retentionBKP-EV-MON-001Holds HOLD · NO-GO until backup monitoring + paging drill captured
Retention period · legal hold alignment
RETENTION_LEGAL_HOLD_REF
Retention / legal holdHead of Evidence · CISO / Head of Evidencen/a — alignmentRetention unverifiedPendingReviewed quarterly + on jurisdiction change——n/an/aPer jurisdictional retention + legal-hold matrixBKP-EV-RET-001Holds HOLD · NO-GO until retention aligns end-to-end with regulator-required retention
Recovery approval · go-live authority
RECOVERY_AUTHORITY_REF
Recovery authorityFounder Office · CISO / Founder Officen/a — authorityMissingPendingReviewed on each cutover decision——n/an/aLifetime of production systemBKP-EV-AUT-001Holds HOLD · NO-GO until Founder Office + CISO + Platform Lead counter-sign captured

Read-only fixture exposed via /api/backup-restore-recovery-evidence; reference NAMES, presence flags, owner, custodian, custody model, approval state, backup cadence, last-backup date, last restore drill date, RPO/RTO targets, measured RPO/RTO, retention / legal-hold posture, and evidence references only. Cross-references /api/production-config-readiness, /api/production-ingress-route-readiness, /api/secret-rotation-key-custody, and /api/jurisdictional-permissions-matrix. Mirrored summary in the Final Production Launch Control Tower, the Operational Runbooks & Day-2 Support Centre, the Data Governance & Retention Centre, the Production Monitoring Centre, and the Completeness Command Centre. Internal backup/recovery readiness posture only — not security certification, not regulatory approval, not legal advice, not audit opinion, not compliance certification, not regulator submission, not permission grant, not launch authorisation, not client acceptance, not external endpoint authorisation, and not external-use authorisation. Staging or demo backups do not count as production recovery evidence.

Production Observability, SLO & Incident Evidence Loop

Health checks · SLOs · alert routing · SIEM · incident command · PIR · escalation · notification triggers

Observability & incident rule: No monitoring token, webhook secret, SIEM ingest key, PagerDuty / Opsgenie API key, on-call paging number, private monitoring endpoint, production log line, customer data, incident room URL, regulator/board notification channel, or live alert payload appears in this register, in the API at /api/observability-slo-incident-evidence, in the fixture, or in any commit. Only ownership, declared (non-secret) reference NAMES, presence flags, approval state, SLO targets, measured values where captured, alert route names, last alert-test dates, last incident-drill dates, log retention evidence references, linked runbook / escalation paths, notification trigger statuses, evidence references, and unlock criteria are recorded. Staging or demo monitoring does not count as production observability evidence. Internal observability / incident readiness posture only — not security certification, not regulatory approval, not legal advice, not audit opinion, not compliance certification, not regulator submission, not permission grant, not launch authorisation, not client acceptance, not capital/liquidity adequacy, not external endpoint authorisation, not incident notification submission, and not external-use authorisation.
Controls assessed
25
Health · SLOs · dependencies · alert routing · IC · SIEM · detection · export · notify · PIR · escalation · comms · chaos · maintenance · authority
Ready · internal
0
Owner + approval + SLO measurement + tested route + logging + PIR captured
SLO unverified
8
Targets declared · measurement not captured against production-grade probe
Alert route untested
25
Paging / channel route test not captured within freshness window
Logging unverified
2
SIEM forwarder / retention not evidenced end-to-end
PIR / drill untested
2
Post-incident review / chaos drill not within freshness window
Escalation / notify pending
25
Runbook + escalation path + trigger status not approved end-to-end
Missing / blocked
13
Required observability / incident evidence not captured
Production launch
HOLD · NO-GO
Until SLO + routes + SIEM + IC + PIR + escalation + notify + authority captured
Control Group Owner State Approval SLO target Measured value Alert route Last route test Last incident drill Runbook Escalation path Notify trigger Evidence Launch impact
Production liveness health check
OBS_HEALTH_LIVENESS_REF
Health · syntheticPlatform LeadMissingPendingProbe response < 2s · 99%/30d—OBS-ROUTE-PRIMARY——RB-INC-LIVENESSESC-INC-TIER1PendingOBS-EV-HC-001Holds HOLD · NO-GO until probe bound + SLO measured + route tested
Production readiness health check
OBS_HEALTH_READINESS_REF
Health · syntheticPlatform LeadMissingPendingProbe response < 5s · 99%/30d—OBS-ROUTE-PRIMARY——RB-INC-READINESSESC-INC-TIER1PendingOBS-EV-HC-002Holds HOLD · NO-GO until readiness probe + SLO measured + route tested
End-to-end synthetic transaction probe
OBS_SYNTHETIC_E2E_REF
Health · syntheticPlatform LeadMissingPendingCritical path ≥ 99.5%/30d—OBS-ROUTE-PRIMARY——RB-INC-E2EESC-INC-TIER1PendingOBS-EV-HC-003Holds HOLD · NO-GO until E2E probe bound + measured
Uptime SLO target & measurement
OBS_SLO_UPTIME_REF
SLO · targetsPlatform LeadSLO unverifiedPendingUptime ≥ 99.9%/30d—OBS-ROUTE-PRIMARY——RB-INC-SLO-UPTIMEESC-INC-TIER1PendingOBS-EV-SLO-001Holds HOLD · NO-GO until measured uptime within target + burn-rate alert bound
Latency SLO target & measurement
OBS_SLO_LATENCY_REF
SLO · targetsPlatform LeadSLO unverifiedPendingp95 < 1.5s · p99 < 3s—OBS-ROUTE-PRIMARY——RB-INC-SLO-LATENCYESC-INC-TIER1PendingOBS-EV-SLO-002Holds HOLD · NO-GO until measured p95/p99 within target
Error-rate SLO target & measurement
OBS_SLO_ERROR_REF
SLO · targetsPlatform LeadSLO unverifiedPending5xx ≤ 0.1%/30d—OBS-ROUTE-PRIMARY——RB-INC-SLO-ERRORESC-INC-TIER1PendingOBS-EV-SLO-003Holds HOLD · NO-GO until measured 5xx within target
Entra OIDC dependency monitor
OBS_DEP_ENTRA_REF
Dependency monitorCISOMissingPendingSign-in ≥ 99.9% / p95 < 2s—OBS-ROUTE-SECURITY——RB-INC-ENTRAESC-INC-TIER1PendingOBS-EV-DEP-001Holds HOLD · NO-GO until Entra availability + sign-in failure detection captured
Production database dependency monitor
OBS_DEP_DB_REF
Dependency monitorPlatform LeadMissingPendingDB ≥ 99.95% · query p95 < 500ms—OBS-ROUTE-PRIMARY——RB-INC-DBESC-INC-TIER1PendingOBS-EV-DEP-002Holds HOLD · NO-GO until DB availability + replication alert captured
Partner route dependency monitor
OBS_DEP_PARTNER_REF
Dependency monitorPlatform LeadMissingPendingPartner-route ≥ 99.5%/30d—OBS-ROUTE-PRIMARY——RB-INC-PARTNERESC-INC-TIER1PendingOBS-EV-DEP-003Holds HOLD · NO-GO until partner heartbeat + reachability captured
Primary alert routing & on-call rota
OBS_ALERT_PRIMARY_REF
Alert routingCISOAlert route untestedPendingAck ≤ 15m · 24/7—OBS-ROUTE-PRIMARY——RB-INC-ON-CALLESC-INC-TIER1PendingOBS-EV-ALERT-001Holds HOLD · NO-GO until paging route + rota tested end-to-end
Security alert routing
OBS_ALERT_SECURITY_REF
Alert routingCISOAlert route untestedPendingSec event ack ≤ 15m · 24/7—OBS-ROUTE-SECURITY——RB-INC-SECESC-INC-SECPendingOBS-EV-ALERT-002Holds HOLD · NO-GO until security paging route tested + counter-signed
Incident command room & role allocation
OBS_IC_ROOM_REF
Incident commandCISOMissingPendingIC + scribe + comms ≤ 15m—OBS-ROUTE-PRIMARY——RB-INC-COMMANDESC-INC-TIER1PendingOBS-EV-IC-001Holds HOLD · NO-GO until IC room + roles + severity matrix counter-signed
Per-severity incident runbook
OBS_IC_RUNBOOK_REF
Incident commandCISOIn reviewIn reviewSEV-1/2/3/4 coverage—OBS-ROUTE-PRIMARY——RB-INC-SEVESC-INC-TIER1PendingOBS-EV-IC-002Holds HOLD · NO-GO until per-severity runbook approved + drilled
Audit log · SIEM forwarder
OBS_SIEM_FORWARDER_REF
Audit log · SIEMCISOLogging unverifiedPendingForwarder success ≥ 99.95%/30d—OBS-ROUTE-SECURITY——RB-INC-SIEMESC-INC-SECPendingOBS-EV-LOG-001Holds HOLD · NO-GO until SIEM forwarder + retention + failure alert tested
Audit log retention & immutability
OBS_LOG_RETENTION_REF
Audit log · SIEMCISOLogging unverifiedPendingPer jurisdictional matrix · lock—OBS-ROUTE-SECURITY——RB-INC-LOG-RETENTIONESC-INC-SECPendingOBS-EV-LOG-002Holds HOLD · NO-GO until retention + immutability lock + legal-hold evidenced
Sign-in anomaly detection
OBS_SEC_DETECT_SIGNIN_REF
Security detectionCISOMissingPendingDetect ≤ 5m · page ≤ 15m—OBS-ROUTE-SECURITY——RB-INC-SIGNINESC-INC-SECPendingOBS-EV-SEC-001Holds HOLD · NO-GO until sign-in anomaly rule + route + runbook captured
Break-glass usage detection
OBS_SEC_DETECT_BREAK_GLASS_REF
Security detectionCISOMissingPendingDetect ≤ 1m · page CISO + Founder—OBS-ROUTE-SECURITY——RB-INC-BREAK-GLASSESC-INC-SECPendingOBS-EV-SEC-002Holds HOLD · NO-GO until break-glass detection + paging + runbook captured
Evidence export · bundle anomaly monitor
OBS_EVIDENCE_EXPORT_MON_REF
Evidence export monitorHead of EvidenceMissingPendingAnomaly ≤ 5m—OBS-ROUTE-SECURITY——RB-INC-EXPORTESC-INC-SECPendingOBS-EV-EXP-001Holds HOLD · NO-GO until export / share-link anomaly monitor captured
Regulator · board · stakeholder notification triggers
OBS_NOTIFY_MATRIX_REF
Notification triggersFounder OfficeIn reviewIn reviewSEV-1/2/3/4 → recipients—OBS-ROUTE-EXEC——RB-INC-NOTIFYESC-INC-EXECPendingOBS-EV-NOTIFY-001Holds HOLD · NO-GO until trigger matrix approved + drill-tested; nothing here auto-files a notification
Post-incident review · PIR evidence
OBS_PIR_REF
Post-incident reviewCISOPIR untestedPendingPIR ≤ 10 business days—OBS-ROUTE-EXEC——RB-INC-PIRESC-INC-EXECPendingOBS-EV-PIR-001Holds HOLD · NO-GO until PIR rehearsal evidence + corrective action captured
Escalation SLA · cross-tier hand-off
OBS_ESCALATION_SLA_REF
Escalation SLACISOIn reviewIn reviewDetect 5m / ack 15m / engage 30m / escalate 60m—OBS-ROUTE-PRIMARY——RB-INC-ESCALATIONESC-INC-TIER1PendingOBS-EV-ESC-001Holds HOLD · NO-GO until escalation SLA approved + drilled + counter-signed
Customer · stakeholder comms template
OBS_COMMS_TEMPLATE_REF
Comms templateFounder OfficeMissingPendingPer SEV + channel · pre-approved—OBS-ROUTE-EXEC——RB-INC-COMMSESC-INC-EXECPendingOBS-EV-COMMS-001Holds HOLD · NO-GO until comms templates approved + rehearsed; nothing here auto-sends
Chaos · failure injection drill
OBS_CHAOS_DRILL_REF
Chaos drillPlatform LeadPIR untestedPendingQuarterly chaos exercise—OBS-ROUTE-PRIMARY——RB-INC-CHAOSESC-INC-TIER1n/aOBS-EV-CHAOS-001Holds HOLD · NO-GO until chaos drill performed + counter-signed
Maintenance window · change freeze
OBS_MAINT_FREEZE_REF
Maintenance windowPlatform LeadIn reviewIn reviewMaintenance window + freeze declared—OBS-ROUTE-EXEC——RB-INC-MAINTENANCEESC-INC-TIER1PendingOBS-EV-MAINT-001Holds HOLD · NO-GO until maintenance window + change freeze approved + counter-signed
Incident authority · go-live acceptance
OBS_INC_AUTHORITY_REF
Incident authorityFounder OfficeMissingPendingAuthority + counter-sign + go/no-go—OBS-ROUTE-EXEC——RB-INC-AUTHORITYESC-INC-EXECPendingOBS-EV-AUTH-001Holds HOLD · NO-GO until incident authority counter-sign captured

Read-only fixture exposed via /api/observability-slo-incident-evidence; reference NAMES, presence flags, owner, approval state, SLO targets, measured values, alert route names, last alert-test dates, last incident-drill dates, log retention evidence references, linked runbook / escalation paths, notification trigger statuses, and evidence references only. Cross-references /api/production-config-readiness, /api/production-ingress-route-readiness, /api/secret-rotation-key-custody, /api/backup-restore-recovery-evidence, /api/entra-oidc-readiness, and /api/jurisdictional-permissions-matrix. Mirrored summary in the Final Production Launch Control Tower, the Operational Runbooks & Day-2 Support Centre, the Production Monitoring & Incident Command Centre, the Regulatory Notification & Board Escalation Centre, and the Completeness Command Centre. Internal observability / incident readiness posture only — not security certification, not regulatory approval, not legal advice, not audit opinion, not compliance certification, not regulator submission, not permission grant, not launch authorisation, not client acceptance, not external endpoint authorisation, not incident notification submission, and not external-use authorisation. Staging or demo monitoring does not count as production observability evidence.

Zero-trust policy matrix

Eight zero-trust pillars × readiness & evidence

Conservative posture: Zero-trust readiness below is internal control posture only. It is not a certification, not an attestation against a named industry framework, and not a regulator-recognised approval. External-facing claims require counsel and (where relevant) external assessor sign-off.
Pillar What it requires Readiness Evidence output Owner
Identity Every principal authenticated via Entra OIDC · no anonymous server-to-server calls Entra cutover pending Auth event log · Entra sign-in log (production target) Identity Lead
Device / Session Device posture signal · session age cap · re-auth on high-risk actions Pilot in admin cohort Conditional access decisions · session re-auth log IT Ops · CISO
Network / API Edge WAF · per-route auth · per-route rate-limit · mTLS service-to-service WAF rule pack drafted WAF event sample · rate-limit rejections · mTLS handshake log SRE Lead · CISO
Data Classification Every dataset tagged (Restricted/MNPI · Personal · Internal · Public) · ABAC enforced on access Linked to Data Governance Centre Data inventory tags · access-decision audit log Data Governance Lead
Least Privilege Default deny · JIT elevation · zero standing admin JIT live in pilot Standing-privilege snapshot · JIT elevation log CISO
Continuous Verification Re-evaluate auth/authz on every sensitive action · revoke on signal change Token-level revocation live Continuous-verification event sample Identity Lead
Logging & Telemetry Auth · admin · evidence access · room access · API · WAF all sent to SIEM Pipeline live SIEM index · retention attestation CISO · SRE Lead
Response & Recovery Runbook · paging · containment · revocation · regulator notification trigger Runbook live Incident timeline · revocation evidence · regulator-notify decision CISO
Privileged access & access review

Privileged roles · approvers · expiry · cadence · last review

Privileged role Holder count Approver Expiry / token TTL Review cadence Last review Stale access? Revocation evidence
Founder root 1 Board (dual) Permanent · MFA + re-auth on every privileged action Monthly attestation 2026-05-15 No SEC-EV-AXR-008 § FR
System admin (JIT) 2 CISO + COO 2h JIT · recorded session · auto-revoke Quarterly 2026-05-15 No SEC-EV-AXR-008 § SA
Evidence publisher (21 packs) 4 Head of Evidence 30 d rotation · MFA Quarterly 2026-05-14 No SEC-EV-AXR-008 § EP
Stakeholder room owner 3 Head of Stakeholder Rooms Per-room TTL · MFA Per-share 2026-05-15 No SEC-EV-AXR-008 § RO
Data custodian (Restricted/MNPI) 2 CISO + Data Governance Lead JIT · 4 h · recorded Monthly 2026-05-15 No SEC-EV-AXR-008 § DC
Incident commander (on-call) 3 CISO On-page elevation · time-boxed Quarterly 2026-05-09 Yes — 1 holder rotation overdue SEC-EV-AXR-008 § IC (in progress)
Break-glass 1 CISO + COO (dual) Sealed · open-on-break only · auto-rotate after use Quarterly drill 2026-04-02 Yes — drill overdue (target 2026-05-02) SEC-EV-BREAK-007 (drill pending)
Secrets & key management

Secret class · storage · rotation · last rotation · exposure

Secret class Storage Rotation cadence Last rotation Owner Exposure risk Evidence ref
App signing keys Cloud KMS · HSM-backed 90 d 2026-04-22 Identity Lead Low · key material non-exportable SEC-EV-KEY-001
Service credentials (S2S) Secret manager 60 d 2026-04-30 SRE Lead Low · injected at runtime · no repo exposure SEC-EV-KEY-002
Database credentials Secret manager · IAM-scoped 30 d 2026-05-10 SRE Lead · Data Governance Lead Low SEC-EV-KEY-003
Third-party API keys (vendor inventory) Secret manager · per-vendor scope 90 d 2026-04-15 Head of Procurement · SRE Lead Medium · scope review pending for 1 vendor SEC-EV-KEY-004
Webhook signing secrets Secret manager 180 d 2026-03-12 SRE Lead Low SEC-EV-KEY-005
Evidence-pack encryption keys Cloud KMS · per-pack DEK · KEK rotated 90 d 2026-04-22 Head of Evidence · CISO Low SEC-EV-KEY-006
Stakeholder room link signing Cloud KMS 30 d 2026-05-10 Head of Stakeholder Rooms · CISO Low SEC-EV-KEY-007
JWT signing keys Cloud KMS · key-ID rotated 30 d 2026-05-08 Identity Lead Low SEC-EV-KEY-008
Backup encryption keys Cloud KMS · BYOK candidate 180 d 2026-02-18 SRE Lead · CISO Watch · rotation due 2026-08-17 SEC-EV-KEY-009
WAF · API · SIEM monitoring

Control · signal · threshold · alert owner · escalation

Control Signal monitored Threshold Current sample State Alert owner Escalation path Evidence event
WAF · OWASP Top 10 rule pack Block / challenge rate per route Block rate < 0.5 % on healthy routes 0.21 % (baseline) Configured SRE Lead SRE Lead → CISO on sustained > 1 % WAF-EV-001
WAF · custom rule pack (auth · evidence export · upload) Hits on custom rule IDs 0 hits on critical IDs 0 (baseline) Drafted · pending test CISO · SRE Lead Auto-page CISO on any critical-ID hit WAF-EV-002
API rate-limit (per route · per tenant) Rejections / 1 m < 50 rejections / m on healthy routes 12 (baseline) Enforced SRE Lead SRE Lead API-EV-003
API auth-failure spike 401/403 burst per IP / per principal < 20 / m / principal 2 (baseline) Enforced CISO Auto-page on > 20 / m API-EV-004
SIEM · admin action stream High-risk admin actions per hour All actions captured · 0 dropped 14 / h captured · 0 dropped Configured CISO CISO → COO on anomalous burst SIEM-EV-005
SIEM · evidence-pack access Read/write/export events 100 % capture 2,841 captured / 7 d Configured Head of Evidence · CISO Anomaly triage via Model Governance SIEM-EV-006
SIEM · stakeholder-room access Off-hours · off-device · scope changes 100 % capture 1,193 captured / 7 d Configured Head of Stakeholder Rooms · CISO Auto-page CISO on off-device + restricted scope SIEM-EV-007
SIEM · DLP / data egress Restricted-class data leaving boundary 0 unauthorised egress 0 Pending test Data Governance Lead · CISO Auto-block · auto-page CISO SIEM-EV-008
Vulnerability management & secure SDLC

Dependency · static · secret scan · infra review · release · remediation

Check Tool / signal Owner Cadence Last run Open issues Remediation SLA Exception handling State
Dependency scan SCA · SBOM diff per release SRE Lead Per release + nightly 2026-05-15 2 P3 (transitive) P0 ≤ 24h · P1 ≤ 7d · P2 ≤ 30d · P3 ≤ 90d CISO sign-off required Watch
Static analysis SAST · ruleset pinned per release SRE Lead Per release 2026-05-15 0 Same SLA tiers CISO sign-off Enforced
Secret scan Pre-commit · CI · history scan SRE Lead Every push 2026-05-15 0 P0 immediate rotation Block-on-detect Enforced
Infrastructure review IaC scan · CIS-aligned rules SRE Lead · CISO Per IaC PR 2026-05-14 1 P3 (logging-retention drift) Same SLA tiers CISO sign-off Watch
Release approval Approval & Sign-Off + Release Control gate Programme Manager · CISO Per release 2026-05-15 0 n/a No release without dual sign-off Enforced
Remediation SLA tracker Vuln backlog burn-down SRE Lead · CISO Weekly 2026-05-15 3 open · 0 SLA breached Aged-out alerts page CISO Exceptions logged in register Enforced
Exception handling Time-boxed exception with compensating control CISO Per-exception 2026-05-14 1 open exception (WAF rule pending) ≤ 30 d Risk-committee review Exception Granted
Security incident linkage

Links to Production Monitoring · Release Control · Regulatory Escalation · Data Governance · Stakeholder Rooms · Vendor Risk

Jurisdiction · security evidence matrix

ADGM · UK FCA · MAS · MiFID — internal readiness only

Conservative posture: the table below is internal security readiness drafted against jurisdiction expectations. It is not security certification, not legal advice, not regulatory approval, and not audit opinion. Formal external attestation requires an assessor engagement that is not captured here.
Jurisdiction Security focus areas Internal readiness state Evidence output Limitation (draft) Owner
ADGM / FSRA Cyber risk · outsourcing · data-handling · incident notification Drafted Control inventory · access reviews · incident timeline Internal posture only; not FSRA certification. CISO · Head of Regulatory
UK FCA Operational resilience · important business services · incident notification Drafted Resilience runbooks · evidence-pack samples · vendor exit plans Drafted against FCA OpRes; not a substitute for SMF accountability sign-off. CISO · SMF Lead
Singapore / MAS Technology risk · cyber hygiene · third-party risk Drafted IAM controls · SIEM samples · vendor concentration · key rotation Drafted against MAS TRM expectations; not MAS-issued approval. CISO · Data Governance Lead
EU MiFID II / MiFIR Record-keeping · access control · incident traceability (no order routing) Drafted Auth event log · evidence access log · retention attestation Platform does not place orders. Records aligned for evidence retention only. CISO · CFO
Security exception register

Open exceptions · compensating controls · target close

Exception Affected control Severity Owner Compensating control Resolution path Target close State
Missing MFA test on Entra pilot MFA policy Medium CISO Staging factors enforced; Entra cohort gated Complete Entra cutover + MFA enforcement test 2026-06-05 Pending Test
Stale access review (Incident Commander rotation) Access reviews Low CISO Holder bound to MFA + privileged-session log Close Q2 review by 2026-05-22 2026-05-22 Watch
Privileged account without explicit expiry Founder root (permanent) Accepted Board (dual) Re-auth + dual approver on every privileged action Board-recorded accepted risk; monthly attestation Standing accepted risk Exception Granted
Secret rotation overdue (Backup KEK) Backup encryption keys Low SRE Lead Backups encrypted; access constrained Rotate before 2026-08-17 2026-08-17 Watch
SIEM gap — DLP egress pending test SIEM · DLP Medium Data Governance Lead · CISO Restricted-class data tagging + ABAC denies enforced Complete DLP egress test on staging 2026-05-30 Pending Test
Vulnerability SLA — one P3 nearing aged-out alert Dependency scan Low SRE Lead Transitive · no runtime exposure Remediate or accept with risk-committee sign-off 2026-06-02 Watch
WAF custom rule pending sign-off WAF custom rule pack Medium CISO · SRE Lead OWASP pack live; manual review on critical paths CISO sign-off on rule pack; enable in shadow then enforce 2026-05-28 Exception Granted
Unsupported stakeholder-room role request Room recipient roles Low Head of Stakeholder Rooms Request refused · observer role offered as substitute Decline + document; surface in onboarding policy 2026-05-24 Blocked
Break-glass test overdue Break-glass account Medium CISO · COO Sealed account; dual approver on open; auto-rotate Schedule drill + capture evidence + revoke 2026-05-26 Conditional Approval
Audit trail & evidence preservation

Audit log of security control & IAM events

Timestamp (UTC) Actor Security control Action Evidence hash Limitation recorded Next step
2026-05-08 09:12 CISO · Identity Lead IAM control inventory SEC-IAM-BASELINE published sha256:aa11…cc01 "Internal readiness only." Entra cutover plan dated
2026-05-13 14:22 CISO MFA policy SEC-MFA-POLICY-002 drafted sha256:bb22…cc02 "Not MFA certification." Enforce at Entra cutover
2026-05-15 11:05 CISO · Programme Manager Access reviews SEC-AXR-008 Q2 review in progress sha256:cc33…cc03 "Internal." Close stale assignment by 2026-05-22
2026-05-10 03:18 SRE Lead Database credentials SEC-KEY-003 rotated sha256:dd44…cc04 "Internal." Next rotation 2026-06-09
2026-05-14 22:48 SRE Lead WAF OWASP pack WAF-EV-001 baseline captured sha256:ee55…cc05 "Internal." Enable custom rule pack in shadow
2026-05-15 06:30 CISO SIEM evidence-pack access SIEM-EV-006 7d sample preserved sha256:ff66…cc06 "Internal." Weekly anomaly review
2026-05-15 12:00 SRE Lead Vulnerability backlog SEC-VULN-BURN weekly review · 3 open sha256:aa77…cc07 "Internal." Close 1 P3 before 2026-06-02
2026-05-09 17:42 CISO · SRE Lead Security incident runbook SEC-IR-DRILL tabletop completed sha256:bb88…cc08 "Tabletop only; not a live incident." Quarterly cadence
2026-05-15 13:22 Risk Committee Exception register SEC-EXC-REGISTER 9 open exceptions logged sha256:cc99…cc09 "Internal readiness only." Weekly review
2026-05-16 07:40 CISO · COO · CEO Security control owners SEC-ATTESTATION monthly attestation sha256:dd00…cc10 "Internal; not regulatory approval." Re-attest monthly
Production Data Classification & MNPI Boundary Register

Classification level · MNPI posture · clean-team · access boundary · retention · residency · watermark · release authority

Classification & MNPI rule: No real MNPI, client / customer / investor identity, regulator contact, clean-team identity, deal codename in flight, access log line, IP address, device fingerprint, room URL, signed URL, room token, OTP code, watermark salt body, board pack body, board minute body, regulator submission body, privileged legal advice text, privileged work-product, external counsel memo body, customer data, transaction / order data, confidential attachment contents, personal data subject identity, or live notification channel appears in this register, in the API at /api/data-classification-mnpi-boundary-register, in the fixture, or in any commit. Only reference NAMES, classification level labels, MNPI posture labels, recipient class descriptors, ownership, approval forum names, approval state, evidence reference IDs, access boundary rule class descriptors, clean-team requirement class descriptors, retention / legal-hold basis class descriptors, residency / cross-border class descriptors, watermark / classification label class descriptors, linked evidence / control / stakeholder / regulatory dependency endpoint paths, launch impact text, external-use impact text, and unlock criteria are recorded. Staging or demo classifications do not count as production data classification or MNPI boundary evidence. Internal data-classification / MNPI boundary readiness posture only — not data classification authorisation, not MNPI boundary acceptance, not privacy-compliance certification, not data residency authorisation, not clean-team activation, not data-room authorisation, not regulator submission, not launch authorisation, and not external-use authorisation.

Boundaries assessed
15
Ready · internal
0
In review
0
Missing / blocked
0
Classification missing
0
MNPI boundary unresolved
0
Clean-team pending
0
Access boundary unverified
0
Retention · legal hold unverified
0
Watermark missing
0
Residency unresolved
0
Evidence missing
0
External use · boundary
HOLD · NO-GO
Production launch · boundary
HOLD · NO-GO

Read-only fixture exposed via /api/data-classification-mnpi-boundary-register; reference NAMES, classification level labels, MNPI posture labels, recipient class descriptors, ownership, approval forum names, approval state, evidence reference IDs, access boundary rule class descriptors, clean-team requirement class descriptors, retention / legal-hold basis class descriptors, residency / cross-border class descriptors, watermark / classification label class descriptors only. Authoritative row table is rendered in the Data Governance, Retention & Privacy Centre. Mirrored summaries in the Final Production Launch Control Tower, the Regulatory Notification & Board Escalation Centre, the Strategic Risk Register & Scenario Planning Centre, the Stakeholder Rooms · External Evidence Centre, and the Completeness Command Centre. Cross-references /api/approval-authority-register, /api/risk-acceptance-exception-register, /api/stakeholder-evidence-distribution-gate, /api/regulatory-submission-correspondence-gate, /api/evidence-pack-gate-validation, /api/jurisdictional-permissions-matrix, and /api/observability-slo-incident-evidence. Staging or demo classifications do not count as production data classification or MNPI boundary evidence.

Assumptions and Limitations

What this Centre is — and is not

  • Staging / simulated security data. All control identifiers, evidence hashes, audit events, last-test dates, and rotation timestamps shown here are seed values for an internal security readiness workflow. They are not production telemetry, not a live SIEM index, and not a live audit log.
  • Internal security readiness workflow only. This Centre captures BLACKSWAN's internal security posture. It is not security certification, not a SOC 2 / ISO 27001 attestation, not a regulator-issued approval, and not a substitute for an external assessor engagement.
  • Not legal advice. Jurisdiction posture (ADGM / FCA / MAS / MiFID) is drafted by internal owners as readiness only and is pending counsel review. Submissions to any regulator are always reviewed and signed by external counsel and the accountable SMF / senior person.
  • Not an audit opinion. Control owner attestations are internal management attestations. They do not constitute an internal-audit opinion or an external-audit conclusion.
  • Not authorization for external launch. Enforced state means "control is configured and tested internally." External-facing deployment, regulator engagement, and tenant-specific Entra cutover are pre-conditions that are tracked elsewhere and are not implied by any state shown here.