Skip to content

Latest commit

 

History

History
104 lines (83 loc) · 7.01 KB

File metadata and controls

104 lines (83 loc) · 7.01 KB

Infrastructure, Services, and Credential Access

1. External Services & Infrastructure Inventory

The ISSA platform relies on five core third-party cloud services. All accounts are owned and managed by Pine Brook Technologies (pinebrooktechnologies.com).

flowchart TB
    subgraph CloudInfrastructure["Pine Brook Technologies Cloud Infrastructure"]
        Cloudflare["Cloudflare DNS & Registrar\nDomain: issafoundation.co.in\n• SSL/TLS Termination\n• Edge DDoS Protection"]
        Vercel["Vercel Production Hosting\n• Next.js Serverless Execution\n• Edge CDN & Asset Caching\n• Vercel Analytics"]
        NeonDB["Neon Serverless PostgreSQL\n• PostgreSQL 16 DB\n• BYTEA Document Store\n• Connection Pooling"]
        NeonAuth["Neon Auth Identity Provider\n• Email OTP Service\n• JWT/Session Issuer"]
        GitHubOrg["GitHub Organization (pineBrook)\n• Repository: pineBrook/issa\n• Automated Vercel Webhook"]
    end

    Cloudflare -->|Directs Traffic| Vercel
    Vercel -->|SQL over TLS| NeonDB
    Vercel -->|OAuth/OTP API| NeonAuth
    GitHubOrg -->|Auto Deploy on Push| Vercel
Loading

Comprehensive Service Register

Service Provider Function in System Console Access URL Managing Account / Team Failover / Support Tier
Vercel Web hosting, serverless function execution, edge caching, analytics. vercel.com/dashboard Pine Brook Technologies Team Vercel Pro Tier with 99.99% uptime SLA.
Neon PostgreSQL Primary relational database, JSONB content store, binary resume repository. console.neon.tech Pine Brook Technologies Team Serverless auto-scaling, automated continuous backups.
Neon Auth Staff user identity management, email OTP generation and validation. console.neon.tech Pine Brook Technologies Team Native Neon Auth service.
Cloudflare DNS nameserver management for issafoundation.co.in, apex redirect, TLS certs. dash.cloudflare.com Pine Brook Technologies IT Admin Global Anycast DNS with DNSSEC enabled.
GitHub Source code version control, PR reviews, CI workflow triggers. github.com/pineBrook/issa pineBrook GitHub Organization GitHub Enterprise / Team plan.
Unsplash CDN Remote stock imagery delivery for blog posts and hero banners. images.unsplash.com Public CDN Domain whitelisted in next.config.js.
Google Gemini API AI integration (dormant in current release). aistudio.google.com Pine Brook Technologies Cloud Pay-as-you-go API tier.

2. Credential Register (Metadata & Custody Only)

Caution

Zero Plaintext Credentials in Documentation: In accordance with ISO 27001 and SOC 2 best practices, live passwords, connection strings, and private keys are never documented in markdown files. Real secrets must reside exclusively in the organizational password vault (e.g. 1Password / Bitwarden / AWS Secrets Manager) and Vercel Project Settings.

Credential Name Scope Primary Custodian Backup Custodian Vault Location Rotation Frequency
DATABASE_URL (Production) Prod DB Connection Lead Database Admin Technical Owner Org Vault → "ISSA Prod DB" 90 Days / On Departure
DATABASE_URL (Staging) Staging DB Connection DevOps Engineer Lead Database Admin Org Vault → "ISSA Staging DB" 180 Days
NEON_AUTH_COOKIE_SECRET Session Signing Key Security Lead Technical Owner Org Vault → "ISSA Auth Secrets" 90 Days
RESUME_SIGNING_SECRET HMAC File Download Key Security Lead Technical Owner Org Vault → "ISSA Auth Secrets" 90 Days
VERCEL_TOKEN / Deploy Webhook Automated Deployment DevOps Lead Repository Admin GitHub Secrets & Org Vault Annual / On Incident
CLOUDFLARE_API_KEY DNS Automation Lead Network Admin Technical Owner Org Vault → "Cloudflare Admin" Annual

3. Step-by-Step Secret Rotation Runbooks

3.1. Rotating the Database Connection String (DATABASE_URL)

To rotate database credentials with zero downtime:

  1. Log in to the Neon Console.
  2. Navigate to Branches → Main → Roles & Databases.
  3. Create a new database role (e.g., app_user_v2) with strong auto-generated password.
  4. Grant standard application permissions to the new role:
    GRANT SELECT, INSERT, UPDATE, DELETE ON ALL TABLES IN SCHEMA public TO app_user_v2;
    GRANT USAGE, SELECT ON ALL SEQUENCES IN SCHEMA public TO app_user_v2;
  5. Construct the new connection string: postgresql://app_user_v2:<NEW_PASS>@ep-xyz.neon.tech/neondb?sslmode=require.
  6. Open Vercel Dashboard → ISSA Project → Settings → Environment Variables.
  7. Update DATABASE_URL with the new connection string.
  8. Trigger a new deployment or click Redeploy on the active deployment.
  9. Perform a smoke test (load public pages, submit test contact inquiry, log in to panel).
  10. Once verified, return to Neon Console and delete the old database role (app_user_v1).

3.2. Rotating the Resume Signing Secret (RESUME_SIGNING_SECRET)

  1. Generate a new cryptographically secure 64-character hex string:
    node -e "console.log(require('crypto').randomBytes(32).toString('hex'))"
  2. Open Vercel Environment Settings and update RESUME_SIGNING_SECRET.
  3. Redeploy the application.
  4. Operational Impact: Any previously generated resume download links sent over email or generated in active sessions will immediately expire. Staff will need to click "Download Resume" in /panel/careers to generate a fresh link.

3.3. Rotating the Neon Auth Cookie Secret (NEON_AUTH_COOKIE_SECRET)

  1. Generate a new 32-byte hex secret.
  2. Update NEON_AUTH_COOKIE_SECRET in Vercel Environment Variables.
  3. Redeploy the application.
  4. Operational Impact: All active staff panel sessions will be invalidated. Staff will simply be prompted to log in again via email OTP at /login.

4. Break-Glass Emergency Access Procedure

In the event of a catastrophic operational failure (e.g. primary administrator account locked, critical DNS misconfiguration, or ransomware attack):

  1. Custodians: Emergency recovery credentials must be split across two separate executive custodians (e.g. Chief Technology Officer and Head of IT).
  2. Accessing the Break-Glass Vault:
    • Access the physical/digital emergency vault located in the company's secure disaster recovery repository.
    • Requires dual authorization (both custodians must provide their cryptographic key fragments).
  3. Post-Incident Remediation:
    • Any use of break-glass credentials automatically triggers an Audit Level 1 Incident.
    • Within 24 hours of incident resolution, all break-glass passwords and API keys must be permanently rotated, and a formal Post-Incident Report (PIR) filed with the Security Committee.