Secure Configuration Profiles
MOD supports a set of compliance frameworks by giving each install a declared environment (a profile) and by enabling the controls that profile needs. Declaring a profile records intent and lists the controls that profile expects; it does not configure anything by itself, and it is never a compliance claim. MOD enables controls — it does not certify, validate, or attest that an install meets a framework.
What a profile is
A profile is one value inside the platform setting
compliance.declared_environment (a list — an install can declare more
than one). The allowed values live in CORE/API/services/compliance_environments.py
(ALLOWED_ENVIRONMENTS), each profile's needed controls in
ENVIRONMENT_CONTROLS, and each control's description in CONTROL_CATALOG.
| Profile key | Framework it names |
|---|---|
none | nothing declared |
cmmc | CMMC 2.0 (defense, CUI) |
fedramp_moderate | FedRAMP-aligned Moderate (NIST 800-53 rev5) |
fedramp_high_il5 | FedRAMP-aligned High / DoD IL5 |
iso27001 | ISO/IEC 27001:2022 (Annex A) |
soc2 | SOC 2 (TSC) |
tpn | TPN (MPA / studio) |
privacy | Privacy (GDPR / CCPA) |
hipaa | HIPAA (45 CFR 164 Subpart C posture) |
ferpa_coppa | Education / under-13 (FERPA, COPPA) |
pci_dss | PCI DSS 4.0 (payment-card posture) |
cjis | CJIS (state criminal-justice information) |
iec62443_nerc | Industrial (IEC 62443 / NERC CIP adjacent) |
itar_ear | Export-controlled (ITAR / EAR) |
legal_privilege | Legal privilege (ABA 1.6(c) posture) |
eu_ai_act | EU AI Act (transparency + logging) |
Picking and applying a profile
- Read the current declaration —
GET /v1/platform/settings/compliance/declared-environmentreturns the declared profiles, the controls each one needs, and which of those controls the product provides on this edition. - Set the declaration —
PATCH /v1/platform/settings/compliance.declared_environmentwith{"value": ["cmmc"]}. Unknown profile names are rejected by the registry validator. - Apply the per-profile settings in the tables below. Every key is a
registered platform setting: read with
GET /v1/platform/settings/{key}, write withPATCH /v1/platform/settings/{key}.GET /v1/platform/settingslists the whole registry. - Run the conformance engine —
POST /v1/platform/conformance/run(on demand) or let the scheduler run it everyconformance.run_interval_minutes. Results land in the append-onlyconformance_check_resultstable. - Look at drift —
GET /v1/platform/conformancelists every check with its latest status (pass/fail/manual/error/not-applicable);GET /v1/platform/conformance/historyshows the history, and apass→failflip raises one drift notification per run whenconformance.drift_notifyis on (in-app bell to platform admins plus the tenantconformance.driftwebhook). The CONFORMANCE_DRIFT audit row is written regardless and flows to the SIEM shipper.
The profile_locks control (GY.C1) is the catalog's statement of intent: a
setting a profile requires is meant to be locked, and weakening one while
the profile is declared is rejected with 409 plus an audit row. On a paid
install the lock is enforced inside the single settings write path
(services/platform_settings.py calls compliance_profiles.check_profile_lock
before any row is touched, and check_profile_lock_revert before a
clear_setting reverts to a value weaker than required). Tenant-scoped
overrides are not locked — they do not weaken the platform install's posture.
On CE the profile list is informational (enforced: false): the registry
validates values but nothing is refused. Keys marked "no automated check yet"
below are settings the profile expects that the conformance engine does not
score today; they are manual either way.
Which profiles lock, and what each one locks
Only the seven ids in ALLOWED_PROFILES
(services/compliance_profiles.py) can lock a setting: cmmc,
fedramp_moderate, fedramp_high_il5, iso27001, soc2, tpn, privacy.
The vertical industry environments (hipaa, ferpa_coppa, pci_dss,
cjis, iec62443_nerc, itar_ear, legal_privilege, eu_ai_act) are
needs-list only — declaring one records intent and drives controls, but it
never locks a setting.
Requirement encodings in PROFILE_REQUIRED_SETTINGS, compared against the
setting's registered type:
| Encoding | Meaning |
|---|---|
true | bool setting must be True |
eq <v> | value must equal <v> |
min <n> | int setting must be >= <n> (lower bound) |
max <n> | int setting must be <= <n> (upper bound) |
non_empty_str | string setting must be non-empty |
Session-lifetime semantics: an idle session bound and a max lifetime
bound are max (the session may not exceed them); the access token
lifetime is a min (profiles want tokens long enough that SSO integrations
do not re-prompt per call).
| Profile | Setting key | Requirement | Disruptive |
|---|---|---|---|
cmmc | auth.mfa_required_for_admins | true | yes |
cmmc | auth.mfa_required_for_all | true | yes |
cmmc | auth.phishing_resistant_only | true | yes |
cmmc | auth.sso_session_idle_seconds | max 900 | yes |
cmmc | auth.sso_session_max_lifetime_seconds | max 28800 | yes |
cmmc | auth.access_token_lifespan_seconds | min 900 | no |
cmmc | auth.inactive_disable_days | min 90 | yes |
cmmc | auth.login_banner_text | non_empty_str | no |
cmmc | egress.sealed_mode | true | no |
cmmc | egress.external_llm_enabled | true | no |
cmmc | labels.block_external_llm | true | no |
cmmc | security.stack_tokens_fail_closed | true | no |
cmmc | access_review.schedule_enabled | true | no |
fedramp_moderate | auth.mfa_required_for_admins | true | yes |
fedramp_moderate | auth.mfa_required_for_all | true | yes |
fedramp_moderate | auth.phishing_resistant_only | true | yes |
fedramp_moderate | auth.sso_session_idle_seconds | max 900 | yes |
fedramp_moderate | auth.sso_session_max_lifetime_seconds | max 28800 | yes |
fedramp_moderate | auth.inactive_disable_days | min 35 | yes |
fedramp_moderate | auth.login_banner_text | non_empty_str | no |
fedramp_moderate | egress.external_llm_enabled | true | no |
fedramp_moderate | labels.block_external_llm | true | no |
fedramp_moderate | gsec.transport.internal_tls_enforce | eq require | no |
fedramp_moderate | access_review.schedule_enabled | true | no |
fedramp_high_il5 | auth.mfa_required_for_admins | true | yes |
fedramp_high_il5 | auth.mfa_required_for_all | true | yes |
fedramp_high_il5 | auth.phishing_resistant_only | true | yes |
fedramp_high_il5 | auth.x509_enabled | true | no |
fedramp_high_il5 | auth.sso_session_idle_seconds | max 300 | yes |
fedramp_high_il5 | auth.sso_session_max_lifetime_seconds | max 14400 | yes |
fedramp_high_il5 | auth.inactive_disable_days | min 35 | yes |
fedramp_high_il5 | auth.lockout_max_failures | max 3 | yes |
fedramp_high_il5 | auth.lockout_window_min | max 15 | yes |
fedramp_high_il5 | auth.lockout_duration_min | min 30 | yes |
fedramp_high_il5 | auth.lockout_permanent_until_admin | true | yes |
fedramp_high_il5 | auth.login_banner_text | non_empty_str | no |
fedramp_high_il5 | egress.sealed_mode | true | no |
fedramp_high_il5 | egress.nim_enabled | true | no |
fedramp_high_il5 | egress.model_download_enabled | true | no |
fedramp_high_il5 | egress.external_llm_enabled | true | no |
fedramp_high_il5 | labels.block_external_llm | true | no |
fedramp_high_il5 | gsec.transport.internal_tls_enforce | eq require | no |
fedramp_high_il5 | security.stack_tokens_fail_closed | true | no |
fedramp_high_il5 | worker.egress_proxy_mode | eq enforce | no |
fedramp_high_il5 | access_review.schedule_enabled | true | no |
iso27001 | auth.mfa_required_for_admins | true | yes |
iso27001 | auth.mfa_required_for_all | true | yes |
iso27001 | auth.sso_session_idle_seconds | max 900 | yes |
iso27001 | auth.sso_session_max_lifetime_seconds | max 28800 | yes |
iso27001 | auth.inactive_disable_days | min 90 | yes |
iso27001 | auth.login_banner_text | non_empty_str | no |
iso27001 | labels.block_external_llm | true | no |
iso27001 | gsec.transport.internal_tls_enforce | eq require | no |
iso27001 | access_review.schedule_enabled | true | no |
soc2 | auth.mfa_required_for_admins | true | yes |
soc2 | auth.mfa_required_for_all | true | yes |
soc2 | auth.sso_session_idle_seconds | max 900 | yes |
soc2 | auth.sso_session_max_lifetime_seconds | max 28800 | yes |
soc2 | labels.block_external_llm | true | no |
soc2 | access_review.schedule_enabled | true | no |
tpn | auth.mfa_required_for_admins | true | yes |
tpn | auth.mfa_required_for_all | true | yes |
tpn | auth.login_banner_text | non_empty_str | no |
tpn | auth.sso_session_idle_seconds | max 900 | yes |
tpn | labels.block_external_llm | true | no |
tpn | access_review.schedule_enabled | true | no |
privacy | auth.mfa_required_for_admins | true | yes |
privacy | auth.mfa_required_for_all | true | yes |
privacy | auth.sso_session_idle_seconds | max 900 | yes |
privacy | labels.block_external_llm | true | no |
privacy | egress.external_llm_enabled | true | no |
privacy | privacy.erasure_job_enabled | true | no |
privacy | access_review.schedule_enabled | true | no |
When more than one profile is active, the requirement for a shared key is the
stricter one (_merge_requirement: tighter max, higher min, true,
non_empty_str, eq), so an install declaring cmmc and iso27001 together
locks auth.inactive_disable_days at min 90.
One note to know about before relying on the map:
auth.session_max_concurrent(registered asSESSION_LIMIT_SETTING_KEY, int, default0, groupauth) is in the disruptive list but is not required by any profile, so it is only disruptive if a profile ever comes to require it.
Preview and apply
The lock map is a checklist until it is applied, and applying it is an explicit, two-step, audited operation — setting the profile list never changes a setting by itself.
- Set the active list —
PUT /v1/platform/compliance/profileswith{"profiles": ["cmmc"]}(platform admin). The response reportsweaker_settings: the keys currently below what the profile requires, none of them changed by the call.GET /v1/platform/compliance/profiles(platform admin or a time-boxed auditor) shows each profile's required settings with the current value and pass/fail. - Preview —
POST /v1/platform/compliance/profiles/previewwith{"profiles": ["cmmc"]}. Read-only: it returns exactly the settings that would change (setting,current,value), which of them aredisruptive,disruptive_count,grace_days,grace_deadlineand apreview_hash. - Apply —
POST /v1/platform/compliance/profiles/applywith{"profiles": ["cmmc"], "preview_hash": "<hash from step 2>"}. The call requires fresh re-authenticated auth, recomputes the preview from current state, and 409s (reason: stale_preview, pluswould_change) if any setting or the profile list drifted since the preview — nothing is written in that case. Otherwise each previewed setting is written through the single audited settings write path, one audit row per changed setting plus a summary row.
Disruptive items are the ones that bite running users: forced MFA enrolment,
shortened session bounds, lockout and inactive-disable —
auth.mfa_required_for_admins, auth.mfa_required_for_all,
auth.phishing_resistant_only, auth.sso_session_idle_seconds,
auth.sso_session_max_lifetime_seconds, auth.inactive_disable_days,
auth.lockout_max_failures, auth.lockout_permanent_until_admin,
auth.session_max_concurrent. Each carries a
grace deadline of compliance.disruptive_grace_days days (default 14),
recorded per key in compliance.grace_deadlines and surfaced in the
/profiles and /status payloads. The deadline is recorded and audited, not
auto-enforced — nothing forces an enrolment at the deadline.
Weakening a locked setting is refused with 409 and an audit row naming the
profile and the requirement; the same check runs on a clear_setting revert,
because reverting to the registry default can be a weakening. Preview target
values always meet the requirement, so a previewed write never trips the lock
— only a manual PATCH /v1/platform/settings/{key} can.
Shared baseline keys
Several keys repeat across profiles because the controls behind them are
shared (enforced_mfa, session_controls, login_banner, data_labels,
tls_mtls, conformance_engine, hardened_deploy). They appear in each
profile table so each table stands on its own.
none — nothing declared
The default (compliance.declared_environment = []) declares no profile.
No profile lock applies, so any setting can be moved freely, and the
conformance engine still runs whatever checks are registered. Nothing here
means the install is secure or unsafe — it means MOD has no declared intent
to compare the install against.
cmmc — CMMC 2.0
| Setting key | Recommended value | Why | Verified by |
|---|---|---|---|
auth.mfa_required_for_admins | true | Platform admins must carry a TOTP device (IA-2 / A.9.4.3). | admin_mfa_enforced |
auth.mfa_required_for_all | true for the gov/DoD buyer tier | Realm-wide OTP enrollment; machine users stay exempt. | no automated check yet |
auth.login_banner_text | non-empty authorized-use text | AC-8 use notification on the login page. | no automated check yet |
auth.sso_session_idle_seconds | 900 | AC-11: end an idle session after 15 minutes. | no automated check yet |
auth.sso_session_max_lifetime_seconds | 28800 | AC-12: 8-hour hard session ceiling. | no automated check yet |
auth.access_token_lifespan_seconds | 900 | AC-12: access tokens live no more than 15 minutes. | no automated check yet |
auth.x509_enabled | false (default) | PIV/CAC seam is a no-op until implemented; do not expect it. | no automated check yet |
labels.block_external_llm | true (default) | Labelled (CUI/restricted/EAR/ITAR) content never reaches an external LLM. | labels_block_external_llm |
audit.chain_verify_interval_minutes | 60 (any positive) | Scheduled HMAC audit-chain verification, no recorded break. | audit_chain_verify |
conformance.run_interval_minutes | 360 (default) | Continuous conformance runs on a schedule. | no automated check yet |
conformance.drift_notify | true (default) | A setting flipped off shows up as a drift alert, not silence. | no automated check yet |
CMMC also expects keycloak_native_mfa (admins configuring MFA directly on
Keycloak, available on every edition), reauth_breakglass, encryption_cmk
and patch_evidence; those are install-level capabilities, not settings.
The break-glass review check auth.break_glass_reviewed scores the
re-auth/break-glass control and needs a recorded follow-up review for every
2FA reset in the last 30 days.
fedramp_moderate — FedRAMP-aligned Moderate
| Setting key | Recommended value | Why | Verified by |
|---|---|---|---|
auth.mfa_required_for_admins | true | Admin OTP enforcement (IA-2). | admin_mfa_enforced |
auth.login_banner_text | non-empty | AC-8 system-use banner. | no automated check yet |
auth.sso_session_idle_seconds | 900 | AC-11 idle termination. | no automated check yet |
auth.sso_session_max_lifetime_seconds | 28800 | AC-12 session ceiling. | no automated check yet |
auth.access_token_lifespan_seconds | 900 | AC-12 token lifetime. | no automated check yet |
gsec.transport.internal_tls_enforce | require | Internal hops must use TLS with the internal CA bundle (SC-8). | internal_tls_enforced |
audit.chain_verify_interval_minutes | 60 | AU-9 audit-chain verification scheduled. | audit_chain_verify |
conformance.run_interval_minutes | 360 | Scheduled conformance runs. | no automated check yet |
conformance.drift_notify | true | Drift is announced to admins and webhooks. | no automated check yet |
fedramp_high_il5 — FedRAMP-aligned High / DoD IL5
Same auth/session and TLS keys as Moderate, plus the sealed, labelled and FIPS-facing additions below.
| Setting key | Recommended value | Why | Verified by |
|---|---|---|---|
auth.mfa_required_for_admins | true | Admin OTP enforcement. | admin_mfa_enforced |
auth.mfa_required_for_all | true | High tier: OTP for every realm user. | no automated check yet |
auth.login_banner_text | non-empty | AC-8 banner. | no automated check yet |
auth.sso_session_idle_seconds | 900 | AC-11 idle termination. | no automated check yet |
auth.sso_session_max_lifetime_seconds | 28800 | AC-12 ceiling. | no automated check yet |
auth.access_token_lifespan_seconds | 900 | AC-12 token lifetime. | no automated check yet |
auth.lockout_max_failures | 3 | AC-7: lock after 3 failed sign-ins. | no automated check yet |
auth.lockout_window_min | 15 | AC-7: failure-count window. | no automated check yet |
auth.lockout_duration_min | 30 | AC-7: 30-min lockout. | no automated check yet |
auth.lockout_permanent_until_admin | true | AC-7: only a platform admin can unlock. | no automated check yet |
gsec.transport.internal_tls_enforce | require | TLS enforced on internal hops. | internal_tls_enforced |
egress.sealed_mode | true | Zero outbound calls for the gated categories (SC-7). | egress_sealed |
labels.block_external_llm | true | Labelled data blocked from external LLMs (AC-3). | labels_block_external_llm |
audit.chain_verify_interval_minutes | 60 | AU-9 chain verification scheduled. | audit_chain_verify |
mesh.acl_enforced | true | Tailnet default-deny policy pushed on every deploy. | mesh_acl_default_deny |
privacy.redaction_profile | strict | PII/PHI scrubbed from logs and LLM-bound text. | no automated check yet |
conformance.run_interval_minutes | 360 | Scheduled conformance runs. | no automated check yet |
conformance.drift_notify | true | Drift fan-out. | no automated check yet |
The fips control behind this profile is a build-level capability, not a
setting — see FIPS mode at install; a stock install has
no FIPS-validated crypto path today.
iso27001 — ISO/IEC 27001:2022
ISO 27001 is the security treatment framework: it wants a documented treatment of every object, an audit trail that cannot be broken, and recovery that is proven rather than assumed. The backup keys below are the settings whose checks carry ISO control ids (A.11.2.4).
| Setting key | Recommended value | Why | Verified by |
|---|---|---|---|
auth.mfa_required_for_admins | true | A.9.4.3 operator protection for admins. | admin_mfa_enforced |
auth.login_banner_text | non-empty | Use notification on the login page. | no automated check yet |
auth.sso_session_idle_seconds | 900 | Session bound (idle). | no automated check yet |
auth.sso_session_max_lifetime_seconds | 28800 | Session bound (absolute). | no automated check yet |
auth.access_token_lifespan_seconds | 900 | Bearer-token lifetime bound. | no automated check yet |
audit.chain_verify_interval_minutes | 60 | A.12.4.1 / AU-9: HMAC chain verified on a schedule. | audit_chain_verify |
mesh.acl_enforced | true | A.9.1.1 access-control policy on the tailnet. | mesh_acl_default_deny |
gsec.transport.internal_tls_enforce | require | A.9.2.3 cryptographic protection in transit. | internal_tls_enforced |
labels.block_external_llm | true | A.11.1.1 information scope: labelled data stays local. | labels_block_external_llm |
privacy.erasure_job_enabled | true | A.11.2.4 the treatment includes erasure of retired data. | privacy_erasure_job |
privacy.erasure_grace_days | 30 (default) | How long after a deletion request bytes may still exist. | no automated check yet |
backup.rpo_target_hours | 24 (default) | A.11.2.4 recovery point: last verified backup this fresh. | backup.recent |
backup.restore_test_max_age_days | 30 (default) | A.11.2.4 a restore proof exists and is recent. | backup.restore_tested |
backup.rto_target_minutes | 240 (default) | A.11.2.4 the measured recovery time is within target. | backup.rto_within_target |
conformance.run_interval_minutes | 360 | Continuous conformance runs. | no automated check yet |
conformance.drift_notify | true | Drift fan-out. | no automated check yet |
0 in any of the three backup.* targets disables that check
(reports not-applicable) — set a real number, not zero, for this profile.
See Backup and restore for how the readings are
produced (backup.sh, restore-test.sh).
soc2 — SOC 2 (TSC)
| Setting key | Recommended value | Why | Verified by |
|---|---|---|---|
auth.mfa_required_for_admins | true | Operational security: admins authenticated with OTP. | admin_mfa_enforced |
auth.sso_session_idle_seconds | 900 | Session bound (idle). | no automated check yet |
auth.sso_session_max_lifetime_seconds | 28800 | Session bound (absolute). | no automated check yet |
auth.access_token_lifespan_seconds | 900 | Bearer-token lifetime bound. | no automated check yet |
audit.chain_verify_interval_minutes | 60 | The audit trail is verified, not just written. | audit_chain_verify |
labels.block_external_llm | true | Labelled content never crosses to an external provider. | labels_block_external_llm |
gsec.transport.internal_tls_enforce | require | Encryption in transit on internal hops. | internal_tls_enforced |
conformance.run_interval_minutes | 360 | Continuous conformance runs. | no automated check yet |
conformance.drift_notify | true | Drift fan-out. | no automated check yet |
SOC 2 is an attestation framework: the assessable artefacts are the
conformance report, the audit log and the assessor grant
plus the OSCAL export at GET /v1/platform/conformance/assessment-results.oscal.json.
tpn — TPN (MPA / studio)
The studio profile adds the delivery-side surface: a forensic watermark ID on deliveries so a leak can be traced back to the account that received it.
| Setting key | Recommended value | Why | Verified by |
|---|---|---|---|
auth.mfa_required_for_admins | true | Admin OTP enforcement. | admin_mfa_enforced |
auth.login_banner_text | non-empty | Use notification on the login page. | no automated check yet |
auth.sso_session_idle_seconds | 900 | Session bound (idle). | no automated check yet |
auth.sso_session_max_lifetime_seconds | 28800 | Session bound (absolute). | no automated check yet |
auth.access_token_lifespan_seconds | 900 | Bearer-token lifetime bound. | no automated check yet |
delivery.watermark_policy | label_only or all | Watermark ID on pre-release (label_only) or every (all) delivery. | no automated check yet |
labels.block_external_llm | true | Labelled content never reaches an external LLM. | labels_block_external_llm |
audit.chain_verify_interval_minutes | 60 | Audit chain verified on a schedule. | audit_chain_verify |
conformance.run_interval_minutes | 360 | Continuous conformance runs. | no automated check yet |
conformance.drift_notify | true | Drift fan-out. | no automated check yet |
delivery.watermark_policy is the ID-only phase: the ID is recorded on the
delivery audit row and returned as the X-MOD-Watermark header; the
delivered bytes are untouched. See Data labels for the
pre-release tag that label_only keys off.
privacy — Privacy (GDPR / CCPA)
| Setting key | Recommended value | Why | Verified by |
|---|---|---|---|
auth.mfa_required_for_admins | true | Admin OTP enforcement. | admin_mfa_enforced |
auth.sso_session_idle_seconds | 900 | Session bound (idle). | no automated check yet |
auth.sso_session_max_lifetime_seconds | 28800 | Session bound (absolute). | no automated check yet |
auth.access_token_lifespan_seconds | 900 | Bearer-token lifetime bound. | no automated check yet |
privacy.erasure_job_enabled | true | The daily erasure (crypto-shred) sweep runs. | privacy_erasure_job |
privacy.erasure_grace_days | 30 (default) | Grace window before retired bytes are purged. | no automated check yet |
privacy.redaction_profile | standard | PII scrubbed from log lines and LLM-bound text. | no automated check yet |
labels.block_external_llm | true | Labelled content stays away from external providers. | labels_block_external_llm |
audit.chain_verify_interval_minutes | 60 | Audit chain verified on a schedule. | audit_chain_verify |
conformance.run_interval_minutes | 360 | Continuous conformance runs. | no automated check yet |
conformance.drift_notify | true | Drift fan-out. | no automated check yet |
The erasure sweep never deletes DB rows (ISO 27001, no hard deletes) — it purges object-store bytes and destroys the tenant encryption key. BYO-S3 tenants are report-only: customer buckets are never touched.
hipaa — HIPAA
| Setting key | Recommended value | Why | Verified by |
|---|---|---|---|
auth.mfa_required_for_admins | true | Admin OTP enforcement. | admin_mfa_enforced |
auth.login_banner_text | non-empty | Use notification on the login page. | no automated check yet |
auth.sso_session_idle_seconds | 900 | Session bound (idle). | no automated check yet |
auth.sso_session_max_lifetime_seconds | 28800 | Session bound (absolute). | no automated check yet |
auth.access_token_lifespan_seconds | 900 | Bearer-token lifetime bound. | no automated check yet |
gsec.transport.internal_tls_enforce | require | PHI protected in transit on internal hops. | internal_tls_enforced |
privacy.redaction_profile | hipaa | PHI-grade redaction on logs and LLM-bound prompts. | no automated check yet |
labels.block_external_llm | true | Labelled PHI never reaches an external LLM. | labels_block_external_llm |
audit.chain_verify_interval_minutes | 60 | The audit trail (21 CFR Part 11 posture) is verified. | audit_chain_verify |
conformance.run_interval_minutes | 360 | Continuous conformance runs. | no automated check yet |
conformance.drift_notify | true | Drift fan-out. | no automated check yet |
privacy.redaction_profile accepts off / standard / hipaa / strict
(utils/pii_redaction.PROFILES). The full PHI-redaction control on the
catalog list (phi_redaction_in_logs, GY.V6) is not a product control
today: the setting above covers the API log filter and the wizard LLM
choke point; NodeRun inputs/outputs, task log tails and the support-chat
path are follow-up work. Legal hold (GY.C15) is a paid-edition control, not
a setting key.
ferpa_coppa — Education / under-13 (FERPA, COPPA)
| Setting key | Recommended value | Why | Verified by |
|---|---|---|---|
auth.mfa_required_for_admins | true | Admin OTP enforcement. | admin_mfa_enforced |
auth.login_banner_text | non-empty | Use notification on the login page. | no automated check yet |
auth.sso_session_idle_seconds | 900 | Session bound (idle). | no automated check yet |
auth.sso_session_max_lifetime_seconds | 28800 | Session bound (absolute). | no automated check yet |
auth.access_token_lifespan_seconds | 900 | Bearer-token lifetime bound. | no automated check yet |
residency.region_pin | us (or the state-law region) | Student records refuse to serve outside the pin. | residency.stores_within_pin, residency.workers_within_pin |
privacy.redaction_profile | hipaa | Minor/student data scrubbed from logs and LLM text. | no automated check yet |
labels.block_external_llm | true | Labelled student content never reaches an external LLM. | labels_block_external_llm |
audit.chain_verify_interval_minutes | 60 | Audit chain verified on a schedule. | audit_chain_verify |
conformance.run_interval_minutes | 360 | Continuous conformance runs. | no automated check yet |
conformance.drift_notify | true | Drift fan-out. | no automated check yet |
residency.region_pin accepts us, eu, or empty (off); with the pin off
both residency checks report not-applicable, so set the pin for this
profile. Parental consent (GY.V7) is not a product control today.
pci_dss — PCI DSS 4.0 (posture)
Card data does not touch MOD. The profile lists what keeps that posture true.
| Setting key | Recommended value | Why | Verified by |
|---|---|---|---|
auth.mfa_required_for_admins | true | Admin OTP enforcement. | admin_mfa_enforced |
auth.sso_session_idle_seconds | 900 | Session bound (idle). | no automated check yet |
auth.sso_session_max_lifetime_seconds | 28800 | Session bound (absolute). | no automated check yet |
auth.access_token_lifespan_seconds | 900 | Bearer-token lifetime bound. | no automated check yet |
gsec.transport.internal_tls_enforce | require | TLS on internal hops. | internal_tls_enforced |
privacy.redaction_profile | strict | No PII leaks into logs or LLM-bound text. | no automated check yet |
audit.chain_verify_interval_minutes | 60 | Audit chain verified on a schedule. | audit_chain_verify |
conformance.run_interval_minutes | 360 | Continuous conformance runs. | no automated check yet |
conformance.drift_notify | true | Drift fan-out. | no automated check yet |
The SAQ-A posture is scored by pci_dss_saq_a_dashboard_no_card_capture,
which scans the shipped Dashboard bundle for in-app card-capture (Stripe.js
Elements) code — it reads no setting key, so there is nothing to set for it.
cjis — CJIS
| Setting key | Recommended value | Why | Verified by |
|---|---|---|---|
auth.mfa_required_for_admins | true | Admin OTP enforcement. | admin_mfa_enforced |
auth.mfa_required_for_all | true | Realm-wide OTP for the state-buyer tier. | no automated check yet |
auth.login_banner_text | non-empty | Use notification on the login page. | no automated check yet |
auth.sso_session_idle_seconds | 900 | Session bound (idle). | no automated check yet |
auth.sso_session_max_lifetime_seconds | 28800 | Session bound (absolute). | no automated check yet |
auth.access_token_lifespan_seconds | 900 | Bearer-token lifetime bound. | no automated check yet |
auth.x509_enabled | false (default) | The PIV/CAC seam is a no-op today; do not assume PIV. | no automated check yet |
residency.region_pin | us | CJIS requires US residency; stores and workers fail closed outside it. | residency.stores_within_pin, residency.workers_within_pin |
gsec.transport.internal_tls_enforce | require | TLS on internal hops. | internal_tls_enforced |
audit.chain_verify_interval_minutes | 60 | Unforgeable audit trail (AU-9). | audit_chain_verify |
labels.block_external_llm | true | Labelled CJIS content never leaves to an external LLM. | labels_block_external_llm |
mesh.acl_enforced | true | Tailnet default-deny policy. | mesh_acl_default_deny |
conformance.run_interval_minutes | 360 | Continuous conformance runs. | no automated check yet |
conformance.drift_notify | true | Drift fan-out. | no automated check yet |
The fips control this profile expects is a build-level capability, not a
setting — see FIPS mode at install.
iec62443_nerc — Industrial (IEC 62443 / NERC CIP adjacent)
| Setting key | Recommended value | Why | Verified by |
|---|---|---|---|
auth.mfa_required_for_admins | true | Admin OTP enforcement. | admin_mfa_enforced |
auth.sso_session_idle_seconds | 900 | Session bound (idle). | no automated check yet |
auth.sso_session_max_lifetime_seconds | 28800 | Session bound (absolute). | no automated check yet |
auth.access_token_lifespan_seconds | 900 | Bearer-token lifetime bound. | no automated check yet |
egress.sealed_mode | true | Zero outbound calls for the gated categories. | egress_sealed |
gsec.transport.internal_tls_enforce | require | Boundary protection on internal hops. | internal_tls_enforced |
audit.chain_verify_interval_minutes | 60 | Audit chain verified on a schedule. | audit_chain_verify |
conformance.run_interval_minutes | 360 | Continuous conformance runs. | no automated check yet |
conformance.drift_notify | true | Drift fan-out. | no automated check yet |
With egress.sealed_mode on, every per-category switch
(egress.nim_enabled, egress.model_download_enabled,
egress.external_llm_enabled, egress.webhooks_enabled,
egress.wizard_internet_enabled, egress.license_phonehome_enabled) is
treated as disabled, so there is nothing else to flip. The plant-side
controls belong to the client's own systems. See
IEC 62443 boundary report.
itar_ear — Export-controlled (ITAR / EAR)
| Setting key | Recommended value | Why | Verified by |
|---|---|---|---|
compliance.export_control_enforced | true | Master switch: EAR/ITAR assets gated to US-person readers and US-person workers. | no automated check yet |
compliance.cui_requires_us_person | true (only with the master switch on) | Extend the US-person gate to CUI-classified assets. | no automated check yet |
compliance.itar_requires_us_residency | true (only with the master switch on) | ITAR work claimable only by a US-person-operated worker in the US zone. | no automated check yet |
residency.region_pin | us | US-only residency for stores and workers. | residency.stores_within_pin, residency.workers_within_pin |
egress.sealed_mode | true | No outbound calls for the gated categories. | egress_sealed |
labels.block_external_llm | true | Labelled export-controlled content never reaches an external LLM. | labels_block_external_llm |
gsec.transport.internal_tls_enforce | require | TLS on internal hops. | internal_tls_enforced |
auth.mfa_required_for_admins | true | Admin OTP enforcement. | admin_mfa_enforced |
auth.mfa_required_for_all | true | Realm-wide OTP. | no automated check yet |
auth.login_banner_text | non-empty | Use notification on the login page. | no automated check yet |
auth.sso_session_idle_seconds | 900 | Session bound (idle). | no automated check yet |
auth.sso_session_max_lifetime_seconds | 28800 | Session bound (absolute). | no automated check yet |
auth.access_token_lifespan_seconds | 900 | Bearer-token lifetime bound. | no automated check yet |
audit.chain_verify_interval_minutes | 60 | Audit chain verified on a schedule. | audit_chain_verify |
mesh.acl_enforced | true | Tailnet default-deny policy. | mesh_acl_default_deny |
conformance.run_interval_minutes | 360 | Continuous conformance runs. | no automated check yet |
conformance.drift_notify | true | Drift fan-out. | no automated check yet |
The three compliance.* keys are the export-control gate: MOD enables
export-control gating; it never certifies compliance with ITAR/EAR. A worker
with an unknown residency zone fails closed. The export-control taxonomy
itself (export_control_tagging) is a paid-edition control, not a setting.
legal_privilege — Legal privilege (ABA 1.6(c) posture)
| Setting key | Recommended value | Why | Verified by |
|---|---|---|---|
auth.mfa_required_for_admins | true | Admin OTP enforcement. | admin_mfa_enforced |
auth.sso_session_idle_seconds | 900 | Session bound (idle). | no automated check yet |
auth.sso_session_max_lifetime_seconds | 28800 | Session bound (absolute). | no automated check yet |
auth.access_token_lifespan_seconds | 900 | Bearer-token lifetime bound. | no automated check yet |
gsec.transport.internal_tls_enforce | require | Duty of confidentiality: TLS on internal hops. | internal_tls_enforced |
privacy.redaction_profile | strict | Client content never appears in logs or LLM-bound text. | no automated check yet |
labels.block_external_llm | true | Labelled client content stays local. | labels_block_external_llm |
audit.chain_verify_interval_minutes | 60 | Audit chain verified on a schedule. | audit_chain_verify |
conformance.run_interval_minutes | 360 | Continuous conformance runs. | no automated check yet |
conformance.drift_notify | true | Drift fan-out. | no automated check yet |
The preservation duty is the legal-hold control (GY.C15, paid edition): the
check legal_hold.retention_respects_holds scans the retention/purge GC
paths for the fail-closed hold gate at every scope and reads no setting key.
eu_ai_act — EU AI Act (transparency + logging)
| Setting key | Recommended value | Why | Verified by |
|---|---|---|---|
labels.block_external_llm | true | Labelled content is kept off external providers. | labels_block_external_llm |
audit.chain_verify_interval_minutes | 60 | The logging posture is verified, not just written. | audit_chain_verify |
conformance.run_interval_minutes | 360 | Continuous conformance runs. | no automated check yet |
conformance.drift_notify | true | Drift fan-out. | no automated check yet |
The transparency log itself (GY.V10) is not a product control today, so this profile has no transparency setting to point at; model documentation and impact assessments remain client-side paperwork.
Controls that are not settings
The profile lists in ENVIRONMENT_CONTROLS mix settings and capabilities.
These are capabilities or build-level items with no setting key, so nothing
in the platform-settings registry toggles them: profile_locks (GY.C1),
enforced_mfa (backed by auth.mfa_required_for_admins),
keycloak_native_mfa, login_banner (backed by
auth.login_banner_text), session_controls (backed by the four
auth.* lifespan keys), reauth_breakglass, fips, encryption_cmk,
tls_mtls (backed by gsec.transport.internal_tls_enforce),
hardened_deploy, conformance_engine (backed by the two
conformance.* keys), access_reviews, patch_evidence, sealed_mode
(backed by egress.sealed_mode), data_labels (backed by
labels.block_external_llm), legal_hold, data_residency_pin (backed by
residency.region_pin), export_control_tagging,
phi_redaction_in_logs, parental_consent, ai_transparency_log.
The available_on field in CONTROL_CATALOG says which edition provides a
control; "none" means the product has no such control today, and a paid
install never claims a control it does not have.
Related pages
- Sealed mode — the air-gapped posture behind
egress.sealed_mode. - Data labels — the label taxonomy behind
labels.block_external_llm. - Identity and sessions — the
auth.*session and MFA keys. - Internal TLS — what
gsec.transport.internal_tls_enforcedoes and needs. - Backup and restore — the readings behind the three
backup.*targets. - FIPS mode at install — the honest state of the
fipscontrol. - SIEM hookup — where conformance and audit rows ship.
- Giving your assessor read-only access — the grant an outside assessor uses.