Zero-Trust Enterprise Engineering
Security Architecture & Governance
Defense-in-Depth Specification • Version 3.1
1. Fernet 256-Bit Envelope Encryption
To execute automated DNS fixes via Cloudflare and GoDaddy APIs without risking credential leakage:
- All third-party tokens and API secrets are encrypted at rest using AES-256 in CBC mode with HMAC-SHA256 authenticated signatures (Fernet cryptography).
- Encryption keys are isolated in hardened environment variables and never checked into version control.
- Client UI views display strictly masked representations (
••••••••••••••••) with secret bytes wiped from browser memory.
2. Anti-SSRF Defense & Domain Normalization
InboundCheck protects internal network perimeters against Server-Side Request Forgery (SSRF):
- All user-supplied domain strings pass through rigorous RFC-compliant domain sanitizers prior to DNS resolution.
- Requests to loopback (
127.0.0.1), private subnets (10.0.0.0/8,192.168.0.0/16), link-local addresses, and cloud metadata services (169.254.169.254) are unconditionally rejected. - DNS query timeouts and concurrency limits protect backend resolvers against DNS amplification vectors.
3. Supabase Row-Level Security (RLS) Isolation
Multi-tenancy is enforced at the PostgreSQL database engine layer:
- Every monitored domain, audit log, failover incident, and DNS fix entry is bound to an authenticated tenant UID.
- Database policies enforce
USING (auth.uid() = user_id) WITH CHECK (auth.uid() = user_id), preventing cross-tenant data access (IDOR / BOLA) even in the event of application logic defects. - All backend API routers mandate cryptographically verified Supabase JWT Bearer tokens before parsing request payloads.
4. Edge Security, CORS & Rate Limiting
Network endpoints are protected by enterprise security controls:
- Sliding-Window Rate Limiter: High-frequency API abuse is throttled (120 requests/minute per authenticated client).
- Security Headers: Responses enforce
X-Frame-Options: DENY,X-Content-Type-Options: nosniff, and strict Content Security Policies. - HMAC Webhook Verification: Shopify order webhooks and Stripe billing events require strict HMAC-SHA256 signature verification prior to execution.
5. Responsible Disclosure Program
We welcome coordinated vulnerability reports from security researchers. Submit findings to: security@inboundcheck.com