Back to InboundCheck
OWASP ASVS Hardened
Zero-Trust Enterprise Engineering

Security Architecture & Governance

Defense-in-Depth Specification • Version 3.1

1. Fernet 256-Bit Envelope Encryption

To execute automated DNS fixes via Cloudflare and GoDaddy APIs without risking credential leakage:

  • All third-party tokens and API secrets are encrypted at rest using AES-256 in CBC mode with HMAC-SHA256 authenticated signatures (Fernet cryptography).
  • Encryption keys are isolated in hardened environment variables and never checked into version control.
  • Client UI views display strictly masked representations (••••••••••••••••) with secret bytes wiped from browser memory.

2. Anti-SSRF Defense & Domain Normalization

InboundCheck protects internal network perimeters against Server-Side Request Forgery (SSRF):

  • All user-supplied domain strings pass through rigorous RFC-compliant domain sanitizers prior to DNS resolution.
  • Requests to loopback (127.0.0.1), private subnets (10.0.0.0/8, 192.168.0.0/16), link-local addresses, and cloud metadata services (169.254.169.254) are unconditionally rejected.
  • DNS query timeouts and concurrency limits protect backend resolvers against DNS amplification vectors.

3. Supabase Row-Level Security (RLS) Isolation

Multi-tenancy is enforced at the PostgreSQL database engine layer:

  • Every monitored domain, audit log, failover incident, and DNS fix entry is bound to an authenticated tenant UID.
  • Database policies enforce USING (auth.uid() = user_id) WITH CHECK (auth.uid() = user_id), preventing cross-tenant data access (IDOR / BOLA) even in the event of application logic defects.
  • All backend API routers mandate cryptographically verified Supabase JWT Bearer tokens before parsing request payloads.

4. Edge Security, CORS & Rate Limiting

Network endpoints are protected by enterprise security controls:

  • Sliding-Window Rate Limiter: High-frequency API abuse is throttled (120 requests/minute per authenticated client).
  • Security Headers: Responses enforce X-Frame-Options: DENY, X-Content-Type-Options: nosniff, and strict Content Security Policies.
  • HMAC Webhook Verification: Shopify order webhooks and Stripe billing events require strict HMAC-SHA256 signature verification prior to execution.

5. Responsible Disclosure Program

We welcome coordinated vulnerability reports from security researchers. Submit findings to: security@inboundcheck.com