Skip to content

Security gap: no penetration testing / red-team program #1151

Description

@gangster

Surfaced by the Security Model spine doc's gap register (docs/learn/spine/the-security-model.md).

Gap (4C: cross-cutting). The defense-in-depth model isn't adversarially validated — controls are asserted, not empirically tested.

Do: establish periodic pentest / red-team exercises against the platform + a sample tenant; feed findings back into the gap register.

Metadata

Metadata

Assignees

No one assigned

    Labels

    securitySecurity hardening, posture, or risk reduction

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions