Controls Library

Technical Security Controls

This library describes control families currently implemented in Strand production architecture. Controls are grouped by operational purpose and include evidence references for diligence workflows.

Categories

5

Published Controls

20

Last Updated

2026-03-04

Access Control

Controls governing privileged access to backend infrastructure and investigation data.

4 controls

Network Allowlisting

Preventive

Inbound administrative access to backend infrastructure is restricted to approved network boundaries.

Security Overview v1.0Network-level controls

Mutual TLS for Privileged Paths

Preventive

Client certificate authentication is required before privileged application-layer access is granted.

Security Overview v1.0Authentication requirements

Multi-Factor Administrative Authentication

Preventive

Privileged access requires OTP-based MFA in addition to credential checks.

Security Overview v1.0Authentication requirements

Least-Privilege Production Access

Preventive

Operational access to production systems is limited to a minimal set of authorized personnel.

Security Overview v1.0Operational security practices

Data Protection

Controls focused on confidentiality, isolation, and residency of investigation data.

4 controls

UK Data Residency Controls

Preventive

Core customer data stores and processing infrastructure are hosted in the UK.

Security Overview v1.0Data residency section

At-Rest Encryption

Preventive

Application database storage applies AES-256 encryption at rest.

Security Overview v1.0Database security section

Transport Encryption

Preventive

Data in transit is protected with TLS 1.2+ between services and user endpoints.

Security Overview v1.0Database and frontend sections

Tenant Isolation via RLS

Preventive

Database row-level security enforces organization and investigation scoping with token-backed identity checks.

Security Overview v1.0Row-level security section

Infrastructure Security

Controls reducing exposure of backend services and protecting service perimeters.

4 controls

Infrastructure Segmentation

Preventive

Frontend and processing environments are segmented so public app paths do not directly expose evidence-processing systems.

Security Overview v1.0Architecture and operational security sections

Layered Traffic Filtering

Preventive

Multiple filtering layers are used to reduce direct-to-origin exposure risk for backend services.

Security Overview v1.0Network-level controls

Route Hardening and Drop Policies

Preventive

Unexpected network routes are dropped to reduce reconnaissance surface and enforce known paths.

Security Overview v1.0Blackhole routing controls

Managed Hosting Protections

Preventive

Frontend hosting includes managed SSL and baseline DDoS mitigation capabilities.

Security Overview v1.0Frontend security section

Application Security

Identity, session, and API-layer controls in the application stack.

4 controls

Managed Authentication Service

Preventive

User authentication is handled through Supabase Auth with token-based sessions.

Security Overview v1.0Frontend and database sections

HTTPS and HSTS Enforcement

Preventive

Transport security headers and HTTPS-only communication are enforced.

Security Overview v1.0Frontend security section

JWT Verification at Data Boundary

Preventive

Token verification is performed as part of database access policy evaluation prior to returning records.

Security Overview v1.0Row-level security section

Credential Hashing via Auth Provider

Preventive

Password handling and hashing controls are delegated to managed authentication infrastructure.

Security Overview v1.0Frontend security section

Operational Security

Monitoring, key management, and response-oriented operational controls.

4 controls

Security Monitoring and Alerting

Detective

Access and network-control telemetry is monitored for anomalous events.

Security Overview v1.0Operational security section

Offline Key Backup Handling

Preventive

Critical client certificate backups are retained on offline hardware for controlled recovery.

Security Overview v1.0Operational security section

Defense-in-Depth Layering

Corrective

Independent control layers are designed so single-control failure does not directly expose customer data.

Security Overview v1.0Executive summary and architecture overview

Customer Security Communication Path

Corrective

Security and trust documentation requests are supported via a direct security contact channel.

Security Overview v1.0Summary contact section