The ISSA platform relies on five core third-party cloud services. All accounts are owned and managed by Pine Brook Technologies (pinebrooktechnologies.com).
flowchart TB
subgraph CloudInfrastructure["Pine Brook Technologies Cloud Infrastructure"]
Cloudflare["Cloudflare DNS & Registrar\nDomain: issafoundation.co.in\n• SSL/TLS Termination\n• Edge DDoS Protection"]
Vercel["Vercel Production Hosting\n• Next.js Serverless Execution\n• Edge CDN & Asset Caching\n• Vercel Analytics"]
NeonDB["Neon Serverless PostgreSQL\n• PostgreSQL 16 DB\n• BYTEA Document Store\n• Connection Pooling"]
NeonAuth["Neon Auth Identity Provider\n• Email OTP Service\n• JWT/Session Issuer"]
GitHubOrg["GitHub Organization (pineBrook)\n• Repository: pineBrook/issa\n• Automated Vercel Webhook"]
end
Cloudflare -->|Directs Traffic| Vercel
Vercel -->|SQL over TLS| NeonDB
Vercel -->|OAuth/OTP API| NeonAuth
GitHubOrg -->|Auto Deploy on Push| Vercel
| Service Provider | Function in System | Console Access URL | Managing Account / Team | Failover / Support Tier |
|---|---|---|---|---|
| Vercel | Web hosting, serverless function execution, edge caching, analytics. | vercel.com/dashboard | Pine Brook Technologies Team | Vercel Pro Tier with 99.99% uptime SLA. |
| Neon PostgreSQL | Primary relational database, JSONB content store, binary resume repository. | console.neon.tech | Pine Brook Technologies Team | Serverless auto-scaling, automated continuous backups. |
| Neon Auth | Staff user identity management, email OTP generation and validation. | console.neon.tech | Pine Brook Technologies Team | Native Neon Auth service. |
| Cloudflare | DNS nameserver management for issafoundation.co.in, apex redirect, TLS certs. |
dash.cloudflare.com | Pine Brook Technologies IT Admin | Global Anycast DNS with DNSSEC enabled. |
| GitHub | Source code version control, PR reviews, CI workflow triggers. | github.com/pineBrook/issa | pineBrook GitHub Organization |
GitHub Enterprise / Team plan. |
| Unsplash CDN | Remote stock imagery delivery for blog posts and hero banners. | images.unsplash.com |
Public CDN | Domain whitelisted in next.config.js. |
| Google Gemini API | AI integration (dormant in current release). | aistudio.google.com | Pine Brook Technologies Cloud | Pay-as-you-go API tier. |
Caution
Zero Plaintext Credentials in Documentation: In accordance with ISO 27001 and SOC 2 best practices, live passwords, connection strings, and private keys are never documented in markdown files. Real secrets must reside exclusively in the organizational password vault (e.g. 1Password / Bitwarden / AWS Secrets Manager) and Vercel Project Settings.
| Credential Name | Scope | Primary Custodian | Backup Custodian | Vault Location | Rotation Frequency |
|---|---|---|---|---|---|
DATABASE_URL (Production) |
Prod DB Connection | Lead Database Admin | Technical Owner | Org Vault → "ISSA Prod DB" | 90 Days / On Departure |
DATABASE_URL (Staging) |
Staging DB Connection | DevOps Engineer | Lead Database Admin | Org Vault → "ISSA Staging DB" | 180 Days |
NEON_AUTH_COOKIE_SECRET |
Session Signing Key | Security Lead | Technical Owner | Org Vault → "ISSA Auth Secrets" | 90 Days |
RESUME_SIGNING_SECRET |
HMAC File Download Key | Security Lead | Technical Owner | Org Vault → "ISSA Auth Secrets" | 90 Days |
VERCEL_TOKEN / Deploy Webhook |
Automated Deployment | DevOps Lead | Repository Admin | GitHub Secrets & Org Vault | Annual / On Incident |
CLOUDFLARE_API_KEY |
DNS Automation | Lead Network Admin | Technical Owner | Org Vault → "Cloudflare Admin" | Annual |
To rotate database credentials with zero downtime:
- Log in to the Neon Console.
- Navigate to Branches → Main → Roles & Databases.
- Create a new database role (e.g.,
app_user_v2) with strong auto-generated password. - Grant standard application permissions to the new role:
GRANT SELECT, INSERT, UPDATE, DELETE ON ALL TABLES IN SCHEMA public TO app_user_v2; GRANT USAGE, SELECT ON ALL SEQUENCES IN SCHEMA public TO app_user_v2;
- Construct the new connection string:
postgresql://app_user_v2:<NEW_PASS>@ep-xyz.neon.tech/neondb?sslmode=require. - Open Vercel Dashboard → ISSA Project → Settings → Environment Variables.
- Update
DATABASE_URLwith the new connection string. - Trigger a new deployment or click Redeploy on the active deployment.
- Perform a smoke test (load public pages, submit test contact inquiry, log in to panel).
- Once verified, return to Neon Console and delete the old database role (
app_user_v1).
- Generate a new cryptographically secure 64-character hex string:
node -e "console.log(require('crypto').randomBytes(32).toString('hex'))"
- Open Vercel Environment Settings and update
RESUME_SIGNING_SECRET. - Redeploy the application.
- Operational Impact: Any previously generated resume download links sent over email or generated in active sessions will immediately expire. Staff will need to click "Download Resume" in
/panel/careersto generate a fresh link.
- Generate a new 32-byte hex secret.
- Update
NEON_AUTH_COOKIE_SECRETin Vercel Environment Variables. - Redeploy the application.
- Operational Impact: All active staff panel sessions will be invalidated. Staff will simply be prompted to log in again via email OTP at
/login.
In the event of a catastrophic operational failure (e.g. primary administrator account locked, critical DNS misconfiguration, or ransomware attack):
- Custodians: Emergency recovery credentials must be split across two separate executive custodians (e.g. Chief Technology Officer and Head of IT).
- Accessing the Break-Glass Vault:
- Access the physical/digital emergency vault located in the company's secure disaster recovery repository.
- Requires dual authorization (both custodians must provide their cryptographic key fragments).
- Post-Incident Remediation:
- Any use of break-glass credentials automatically triggers an Audit Level 1 Incident.
- Within 24 hours of incident resolution, all break-glass passwords and API keys must be permanently rotated, and a formal Post-Incident Report (PIR) filed with the Security Committee.