Security, Risk & Governance
This is the entry point for Stella Ops security documentation: threat models, governance, compliance controls, and security operations. It is written for operators hardening a deployment, auditors reviewing controls, and engineers implementing security-sensitive features.
For the core security guarantee that all ingestion paths uphold — append-only, decision-free aggregation — see aoc-invariants.md.
Policies & Governance
- SECURITY_POLICY.md — responsible disclosure and support windows.
- GOVERNANCE.md — project governance charter.
- CODE_OF_CONDUCT.md — code standards and contributor conduct.
- SECURITY_HARDENING_GUIDE.md — deployment hardening steps.
- coordinated-vulnerability-disclosure.md — CVD policy for vulnerabilities in Stella Ops itself.
- security-txt.md — RFC 9116
security.txttemplate and fail-closed publication runbook. - policy-governance.md — policy governance controls and specifics.
- LEGAL_FAQ_QUOTA.md — legal interpretation of quota.
- QUOTA_OVERVIEW.md — quota policy reference.
Threat Models & Security Architecture
- aoc-invariants.md — Aggregation-Only Contract invariants enforced across ingestion and attestation.
- authority-threat-model.md — Authority service threat analysis.
- authority-scopes.md — Authority scope model.
- scopes-and-roles.md — scope-to-role mapping.
- tenancy-overview.md — tenant isolation model.
- console-security.md — Console posture guidance.
- plugin-sandbox-threat-model.md — plugin sandboxing threat analysis.
- pack-signing-and-rbac.md — pack signing and RBAC guardrails.
- rate-limits.md — rate-limiting behaviour.
- password-hashing.md — credential storage.
- secrets-handling.md — secret material lifecycle and storage.
- trust-and-signing.md — trust roots and signing model.
Audit, Revocation & Compliance
- audit-events.md — audit event taxonomy.
- revocation-bundle.md & revocation-bundle-example.json — revocation process and sample bundle.
- QUOTA_ENFORCEMENT_FLOW.md — quota enforcement sequence.
- OFFLINE_KIT.md — tamper-evident offline artefacts.
- crypto-compliance.md — regional crypto compliance (FIPS/eIDAS/GOST/SM).
Supporting Material
- Module operations security notes: authority/operations/key-rotation.md and concelier/operations/authority-audit-runbook.md.
- zastava/README.md — retirement record for the former Kubernetes runtime-enforcement direction (no longer a live security surface; preserved to disambiguate the reused
Zastavaname).
