Data Governance / Security
You own: security-aspect of governance — access control, secret rotation, threat detection, audit integrity, regulatory alignment.
Threat model snapshot
Full table in security.md. Highlights:
- Compromised runner pod → mitigated by non-root + cap-drop + NetworkPolicy
- Stolen PAT → scoped + audit per use + rotation
- Audit tampering → SHA-256 chain detects
- Cross-tenant data leak →
tenant_ideverywhere + bucket policy
Daily checks
-- Audit chain integrity (all prod tenants)
SELECT tenant_id, (verify_audit_chain(tenant_id)).*
FROM (SELECT DISTINCT tenant_id FROM genedata_audit_log) t;
-- Anomalous auth failures
SELECT count(*) FROM genedata_audit_log
WHERE action='auth.failure' AND ts >= now() - INTERVAL '1 hour';
Weekly checks
| Check | Query / runbook |
|---|---|
New geneflow:admin scoped PATs | WHERE 'geneflow:admin' = ANY(scopes) AND created_at >= now() - 7d |
| Production transitions w/o approval | WHERE approved_by IS NULL AND requested_stage='Production' |
Endpoints with requireApproval=false | WHERE drift_check_enabled=false AND status='READY' (suspicious) |
| Image pulls from non-canonical registries | Falco / Kyverno policy |
Monthly checks
- Access review — see DGL workbook
- Secret rotation — system tokens, image-pull creds, KMS CMK rotation
- DR drill from backup
- Penetration test report review (if external pentest cadence)
Regulatory alignment quick map
| Standard | GeneFlow control |
|---|---|
| SOC2 | Hash-chained audit log + access review queries above |
| GDPR | Per-tenant data residency, audit log shows actor + time, right-to-deletion via tenant teardown |
| HIPAA | Per-tenant KMS CMKs, NetworkPolicy for serving pods, BAA terms in docs/legal/sla.md |
| FedRAMP | Pending — TLS 1.3 throughout, FIPS-validated KMS recommended |
| EU AI Act | Hash-chained audit log of model + prompt transitions = "post-market monitoring" |
Incident playbook
- Detect — alert fires (audit chain broken, anomalous transitions, mass auth failures)
- Triage — within 15 min: confirm real, scope blast radius, declare severity (see INCIDENT-RESPONSE.md)
- Contain — revoke compromised tokens, rotate keys, suspend affected tenants if needed
- Investigate — pull
genedata_audit_logslice + system logs into a timeline - Recover — restore from clean backup if needed
- Postmortem — write within 5 business days using postmortem template
- Notify — GDPR 72h, SOC2 customers per SLA