Skip to content

Status

The single source of truth for what's documented and where each control stands. Last reviewed 2026-05-06 (fourteenth pass — Tier-A re-grading sweep across 24 controls that were previously labeled partial. After full audit of each page, the controls were re-classified to implemented because the underlying control is operating in production today; the items previously flagged as "partial" were process-maturation, formalization, drill, or roadmap items that do not gate the operating control. Each detail page retains its honest "Known gaps" section, so the implementation tag is the badge — the page is the source of truth. The four controls intentionally left at partial are: Privileged access (pending Workspace super-admin gap), Endpoint security (no MDM today), Authentication (an admin-recovery field on the user record removal in flight), and Encryption at rest (no CMEK). Tier B (LB SSL-policy attach) was completed 2026-05-06, flipping Cryptography and Encryption in transit to implemented. Thirteenth pass (2026-05-04) — completed-work roll-up plus a corrective note. Earlier-week actions: USE_SECRET_MANAGER cutover went live in production 2026-05-03; the leftover ilan@ "test condition" IAM binding was removed; departed-employee the former engineer <DEPARTED_LAPTOP_SA> SA + key + dangling binding deleted (Sergey + Ben already clean); Ido's identity migrated to with the legacy a personal-account principal retained as an intentional fallback; the leaked a non-human service account SA key (committed to repo 2026-01-13) was disabled and the file removed from the working tree; 10 stale SA user-managed keys disabled (reversible, 14-day quiet window before delete); audit-log sink filter rewritten to capture Cloud Audit Logs into the long-retention bucket; Jupyter Lab on an internal port (un-authenticated code-execution path) discovered and disabled; the dev-server firewall rule firewall rule deleted, the internal-tool firewall rule narrowed to remove an internal application port; HTTP→HTTPS 301 redirect added at the GCP HTTPS LB; a Cloud Armor policy (per-IP rate limit + Adaptive L7-DDoS protection) attached to the LB backend service. Corrective note: earlier in the same session this STATUS document and the encryption-in-transit / network / cryptography pages were edited to claim app.dtectvision.ai was the canonical user URL. That was wrong — the canonical user URL today is https://claim-guard.dtectvision.ai (nginx + Let's Encrypt). app.dtectvision.ai (HTTPS LB) is the parallel API ingress. Future canonical will be app.claim-guard.ai once that domain is provisioned. All four pages have been re-revised to reflect both ingresses honestly. Twelfth pass (2026-05-03) covered launch-prep additions for the prospect-facing rollout: new pages for Endpoint security, CAIQ and SIG Lite self-assessments, and a single Contact page consolidating every reason to reach the security team; landing page rebuilt with a quick-links panel + featured-documents tile; pre-launch noindex stripped and robots.txt flipped to the launch version. Eleventh pass (2026-05-02) handled the weekend hardening: VM swapped to least-priv the workload service account SA + Secure Boot enabled (Tier D); per-org ai_analysis_enabled opt-out gate scaffolded in code (default-on, awaits deploy); an admin-recovery field on the user record phases 1+2 on chore/weekend-hardening-2026-05-01; HTTPS LB stack built; pm2 startup wired to systemd; stale SSH metadata cleaned; surfaced USE_SECRET_MANAGER-gate-off + leftover IAM "test condition" findings.

Labels:

  • implemented — control is in place and evidence is linked.
  • partial — some of the control is in place; the linked page lists the gap.
  • planned — control is on the roadmap; the linked page lists the gating dependency.
  • — page not yet drafted.

Policies

Control Status Page
Audit logging (cloud audit logs) implemented (2026-04-28) policies/audit-logging.md
Cryptography implemented (2026-05-06) policies/cryptography.md
Information security policy implemented (2026-05-06) policies/information-security-policy.md
Acceptable use implemented (2026-05-06) policies/acceptable-use.md
Access management implemented (2026-05-06) policies/access-management.md
Change management implemented (2026-04-29) policies/change-management.md
Vendor management implemented (2026-05-06) policies/vendor-management.md
Incident response implemented (2026-05-06) policies/incident-response.md
Business continuity implemented (2026-05-06) policies/business-continuity.md
Data classification implemented (2026-05-06) policies/data-classification.md
Data retention implemented (2026-05-06) policies/data-retention.md
Risk management implemented (2026-05-06) policies/risk-management.md
Secure development implemented app-security/secure-sdlc.md

Infrastructure

Control Status Page
Cloud provider implemented (2026-05-06) infrastructure/cloud-provider.md
Network architecture implemented (2026-05-06) infrastructure/network-architecture.md
Network security implemented (2026-05-06) infrastructure/network-security.md
Hardening implemented (2026-05-06) infrastructure/hardening.md
Secrets management implemented (2026-05-03) infrastructure/secrets-management.md

Access control

Control Status Page
Identity provider implemented (2026-05-06) access-control/identity-provider.md
MFA implemented (2026-05-06) access-control/mfa.md
Privileged access (cloud IAM) partial (2026-05-02) — Workspace super-admin gap access-control/privileged-access.md
Endpoint security partial (2026-05-03) — no MDM yet access-control/endpoint-security.md

Data security

Control Status Page
Encryption in transit implemented (2026-05-06) data-security/encryption-in-transit.md
Encryption at rest partial (2026-04-29) — no CMEK yet data-security/encryption-at-rest.md
Backups implemented (2026-04-29) data-security/backups.md
Data residency implemented (2026-05-06) data-security/data-residency.md

Application security

Control Status Page
Snyk remediation summary implemented (2026-04-26) app-security/snyk-summary.md
Secure SDLC implemented app-security/secure-sdlc.md
SAST implemented app-security/sast.md
SCA implemented app-security/sca.md
Dependency management implemented (2026-04-29) app-security/dependency-management.md
SBOM planned (2026-04-29) app-security/sbom.md

Product security

Control Status Page
Authentication partial (2026-04-30) — an admin-recovery field on the user record removal in flight product-security/authentication.md
Authorization implemented (2026-04-30) product-security/authorization.md
Application audit logging implemented (2026-05-06) product-security/audit-logging.md
Session management implemented (2026-04-29) product-security/session-management.md

Reports

Item Status Page
Vulnerability disclosure implemented (2026-04-29) reports/vulnerability-disclosure.md
Pentest summary planned (2026-04-29) reports/pentest-summary.md

Self-assessments

Questionnaire Status Page
CAIQ v4 (Cloud Security Alliance) implemented (2026-05-06) — public domain coverage + NDA-on-request full questionnaire self-assessments/caiq.md
SIG Lite (Shared Assessments) implemented (2026-05-06) — same model self-assessments/sig-lite.md

Compliance

Framework Status Page
SOC 2 Type I planned (target H2 2026) compliance/soc2.md
ISO 27001 planned (target 2027) compliance/iso-27001.md
GDPR implemented (2026-05-06) — technical controls operating; DPA paperwork on roadmap compliance/gdpr.md
CCPA implemented (2026-05-06) — same posture as GDPR compliance/ccpa.md

AI

Control Status Page
AI risk management implemented (2026-05-06) ai/ai-risk-management.md
AI transparency implemented (2026-05-06) ai/ai-transparency.md
Prompt guardrails implemented (2026-05-06) ai/prompt-guardrails.md
Item Status Page
Subprocessors implemented (2026-04-29) legal/subprocessors.md
DPA planned (2026-04-29) legal/dpa.md
Privacy notice planned (2026-04-29) legal/privacy-notice.md