Security Architecture & ASVS L1
11-threat matrix, SecretRedactor pipeline, and SSRF destination policy.
M31A is hardened against 11 canonical security threats in accordance with OWASP ASVS L1 standards.
11 Threat Vectors Hardening Matrix
See the interactive threat explorer on the Security page for detailed attack scenarios and mitigations.
5-Tier Secret Redactor
• Tier 1: Explicit registered mission secrets and API keys.
• Tier 2: Authorization headers, Bearer tokens, and JWT payloads (
eyJ...).• Tier 3: Cloud keys: NVIDIA API keys (
nvapi-*), AWS (AKIA*), GitHub tokens (ghp_*).• Tier 4: Database connection URLs containing passwords (
postgres://user:pass@host/db).• Tier 5: Cryptographic private key PEM blocks (RSA, EC, OpenSSH).
SSRF & Egress Policy
The NetworkDestinationPolicy blocks IPv4/IPv6 loopback, RFC 1918 private subnets, and cloud metadata services (169.254.169.254). Asynchronous DNS pre-validation and step-by-step redirect validation prevent DNS rebinding.
Vulnerability Disclosure
Security vulnerabilities should be reported confidentially through GitHub Security Advisories:
Submit a Confidential Security Advisory