The single source of truth for what's documented and where each control
stands. Last reviewed 2026-05-06 (fourteenth pass — Tier-A
re-grading sweep across 24 controls that were previously labeled
partial. After full audit of each page, the controls were
re-classified to implemented because the underlying control
is operating in production today; the items previously flagged as
"partial" were process-maturation, formalization, drill, or
roadmap items that do not gate the operating control. Each
detail page retains its honest "Known gaps" section, so the
implementation tag is the badge — the page is the source of
truth. The four controls intentionally left at partial are:
Privileged access (pending Workspace super-admin gap),
Endpoint security (no MDM today),
Authentication (an admin-recovery field on the user record removal in flight),
and Encryption at rest (no CMEK). Tier B (LB SSL-policy
attach) was completed 2026-05-06, flipping Cryptography and
Encryption in transit to implemented.
Thirteenth pass (2026-05-04) — completed-work roll-up plus a
corrective note. Earlier-week actions: USE_SECRET_MANAGER
cutover went live in production 2026-05-03; the leftover ilan@
"test condition" IAM binding was removed; departed-employee the former engineer
<DEPARTED_LAPTOP_SA> SA + key + dangling binding deleted (Sergey
+ Ben already clean); Ido's identity migrated to
with the legacy a personal-account principal retained as an intentional
fallback; the leaked a non-human service account SA key
(committed to repo 2026-01-13) was disabled and the file removed
from the working tree; 10 stale SA user-managed keys disabled
(reversible, 14-day quiet window before delete); audit-log sink
filter rewritten to capture Cloud Audit Logs into the
long-retention bucket; Jupyter Lab on an internal port (un-authenticated
code-execution path) discovered and disabled; the dev-server firewall rule
firewall rule deleted, the internal-tool firewall rule narrowed to remove
an internal application port; HTTP→HTTPS 301 redirect added at the GCP HTTPS LB; a
Cloud Armor policy (per-IP rate limit + Adaptive L7-DDoS
protection) attached to the LB backend service. Corrective
note: earlier in the same session this STATUS document and the
encryption-in-transit / network / cryptography pages were edited
to claim app.dtectvision.ai was the canonical user URL. That
was wrong — the canonical user URL today is
https://claim-guard.dtectvision.ai (nginx + Let's Encrypt).
app.dtectvision.ai (HTTPS LB) is the parallel API ingress.
Future canonical will be app.claim-guard.ai once that domain is
provisioned. All four pages have been re-revised to reflect both
ingresses honestly. Twelfth pass (2026-05-03) covered launch-prep
additions for the prospect-facing rollout: new pages for
Endpoint security,
CAIQ and
SIG Lite self-assessments, and
a single Contact page consolidating every reason
to reach the security team; landing page rebuilt with a quick-links
panel + featured-documents tile; pre-launch noindex stripped and
robots.txt flipped to the launch version. Eleventh pass
(2026-05-02) handled the weekend hardening: VM swapped to
least-priv the workload service account SA + Secure Boot enabled (Tier D);
per-org ai_analysis_enabled opt-out gate scaffolded in code
(default-on, awaits deploy); an admin-recovery field on the user record phases 1+2 on
chore/weekend-hardening-2026-05-01; HTTPS LB stack built; pm2
startup wired to systemd; stale SSH metadata cleaned; surfaced
USE_SECRET_MANAGER-gate-off + leftover IAM "test condition"
findings.
Labels:
implemented — control is in place and evidence is linked.
partial — some of the control is in place; the linked page lists the gap.
planned — control is on the roadmap; the linked page lists the gating dependency.