# Security controls

- TLS at the public edge and mTLS binding for institutional capabilities.
- Separate admin and internal API identities; caller-supplied role headers are not trusted.
- OAuth 2.0 client credentials with short-lived, issuer/audience/scope-bound JWTs.
- Contract, partner, legal-entity, tenant, consent, purpose, jurisdiction and resource-scope decisions.
- Durable, database-backed idempotency and atomic distributed quota counters in production.
- Timestamped HMAC provider webhooks, five-minute freshness, event IDs and replay rejection.
- External secret references only; credential material is never stored in registry tables.
- Credential fingerprints, expiry, rotation lineage, revocation and certificate posture.
- Hash-chained audit evidence, structured metrics and traces.
- Ordered event streams, database leases, bounded exponential retry, dead-letter state and approved replay.
- Disclosure policies remove unauthorised fields before signed outbound webhook delivery.
- Gateway authority checks reject accounts, journals, postings and Mission decisions.
- Control Tower operator keys are exchanged for short-lived, HttpOnly, Secure, SameSite-strict, CSRF-bound sessions; long-lived keys are never placed in browser storage.
- Governed API keys use Argon2id verification hashes, optional CIDR restrictions, one-time display, controlled rotation overlap and immediate revocation.
- Control Tower approvals enforce request expiry, request hashes and separation of duties before connection or alert-route activation.
- Control Tower activity is SHA-256 linked and recursively redacts secrets, tokens, passwords, private keys, credentials and raw payloads.
