SECURITY

Autonomy with explicit boundaries.

TrustFix is designed as security infrastructure: separated identities, tenant-scoped records, authenticated access, approval gates, drift checks, and proof after every change.

Dedicated identities

Web, API, scanner, and remediator services use separate Cloud Run identities.

Least privilege

The scanner is read-oriented. Storage mutation is scoped to the disposable demo bucket.

Workspace authorization

Google IAP authenticates users; backend role checks enforce Owner, Admin, Reviewer, and Viewer permissions.

Governed changes

Sensitive changes require an approval record and idempotency key. Unexpected drift aborts execution.

Evidence before answers

A control becomes verified only after the measurable property passes again.

CURRENT SUPPORT BOUNDARY

What the deployed build does today.

Automatic observationStorage IAM, Cloud Run IAM, and internet-exposed administrative firewall ports.

Live governed mutationPublic-access removal for the explicitly named disposable TrustFix bucket.

Approval-only planningCloud Run and firewall findings remain inspectable, but mutation executors stay disabled until dedicated rollback acceptance tests pass.

Never claimedDrive, Gmail, Slack, HR, training, and policy-document evidence without a connected source.