Skip to main content

Secure Configuration Profiles

MOD supports a set of compliance frameworks by giving each install a declared environment (a profile) and by enabling the controls that profile needs. Declaring a profile records intent and lists the controls that profile expects; it does not configure anything by itself, and it is never a compliance claim. MOD enables controls — it does not certify, validate, or attest that an install meets a framework.

What a profile is​

A profile is one value inside the platform setting compliance.declared_environment (a list — an install can declare more than one). The allowed values live in CORE/API/services/compliance_environments.py (ALLOWED_ENVIRONMENTS), each profile's needed controls in ENVIRONMENT_CONTROLS, and each control's description in CONTROL_CATALOG.

Profile keyFramework it names
nonenothing declared
cmmcCMMC 2.0 (defense, CUI)
fedramp_moderateFedRAMP-aligned Moderate (NIST 800-53 rev5)
fedramp_high_il5FedRAMP-aligned High / DoD IL5
iso27001ISO/IEC 27001:2022 (Annex A)
soc2SOC 2 (TSC)
tpnTPN (MPA / studio)
privacyPrivacy (GDPR / CCPA)
hipaaHIPAA (45 CFR 164 Subpart C posture)
ferpa_coppaEducation / under-13 (FERPA, COPPA)
pci_dssPCI DSS 4.0 (payment-card posture)
cjisCJIS (state criminal-justice information)
iec62443_nercIndustrial (IEC 62443 / NERC CIP adjacent)
itar_earExport-controlled (ITAR / EAR)
legal_privilegeLegal privilege (ABA 1.6(c) posture)
eu_ai_actEU AI Act (transparency + logging)

Picking and applying a profile​

  1. Read the current declaration — GET /v1/platform/settings/compliance/declared-environment returns the declared profiles, the controls each one needs, and which of those controls the product provides on this edition.
  2. Set the declaration — PATCH /v1/platform/settings/compliance.declared_environment with {"value": ["cmmc"]}. Unknown profile names are rejected by the registry validator.
  3. Apply the per-profile settings in the tables below. Every key is a registered platform setting: read with GET /v1/platform/settings/{key}, write with PATCH /v1/platform/settings/{key}. GET /v1/platform/settings lists the whole registry.
  4. Run the conformance engine — POST /v1/platform/conformance/run (on demand) or let the scheduler run it every conformance.run_interval_minutes. Results land in the append-only conformance_check_results table.
  5. Look at drift — GET /v1/platform/conformance lists every check with its latest status (pass / fail / manual / error / not-applicable); GET /v1/platform/conformance/history shows the history, and a pass → fail flip raises one drift notification per run when conformance.drift_notify is on (in-app bell to platform admins plus the tenant conformance.drift webhook). The CONFORMANCE_DRIFT audit row is written regardless and flows to the SIEM shipper.

The profile_locks control (GY.C1) is the catalog's statement of intent: a setting a profile requires is meant to be locked, and weakening one while the profile is declared is rejected with 409 plus an audit row. On a paid install the lock is enforced inside the single settings write path (services/platform_settings.py calls compliance_profiles.check_profile_lock before any row is touched, and check_profile_lock_revert before a clear_setting reverts to a value weaker than required). Tenant-scoped overrides are not locked — they do not weaken the platform install's posture. On CE the profile list is informational (enforced: false): the registry validates values but nothing is refused. Keys marked "no automated check yet" below are settings the profile expects that the conformance engine does not score today; they are manual either way.

Which profiles lock, and what each one locks​

Only the seven ids in ALLOWED_PROFILES (services/compliance_profiles.py) can lock a setting: cmmc, fedramp_moderate, fedramp_high_il5, iso27001, soc2, tpn, privacy. The vertical industry environments (hipaa, ferpa_coppa, pci_dss, cjis, iec62443_nerc, itar_ear, legal_privilege, eu_ai_act) are needs-list only — declaring one records intent and drives controls, but it never locks a setting.

Requirement encodings in PROFILE_REQUIRED_SETTINGS, compared against the setting's registered type:

EncodingMeaning
truebool setting must be True
eq <v>value must equal <v>
min <n>int setting must be >= <n> (lower bound)
max <n>int setting must be <= <n> (upper bound)
non_empty_strstring setting must be non-empty

Session-lifetime semantics: an idle session bound and a max lifetime bound are max (the session may not exceed them); the access token lifetime is a min (profiles want tokens long enough that SSO integrations do not re-prompt per call).

ProfileSetting keyRequirementDisruptive
cmmcauth.mfa_required_for_adminstrueyes
cmmcauth.mfa_required_for_alltrueyes
cmmcauth.phishing_resistant_onlytrueyes
cmmcauth.sso_session_idle_secondsmax 900yes
cmmcauth.sso_session_max_lifetime_secondsmax 28800yes
cmmcauth.access_token_lifespan_secondsmin 900no
cmmcauth.inactive_disable_daysmin 90yes
cmmcauth.login_banner_textnon_empty_strno
cmmcegress.sealed_modetrueno
cmmcegress.external_llm_enabledtrueno
cmmclabels.block_external_llmtrueno
cmmcsecurity.stack_tokens_fail_closedtrueno
cmmcaccess_review.schedule_enabledtrueno
fedramp_moderateauth.mfa_required_for_adminstrueyes
fedramp_moderateauth.mfa_required_for_alltrueyes
fedramp_moderateauth.phishing_resistant_onlytrueyes
fedramp_moderateauth.sso_session_idle_secondsmax 900yes
fedramp_moderateauth.sso_session_max_lifetime_secondsmax 28800yes
fedramp_moderateauth.inactive_disable_daysmin 35yes
fedramp_moderateauth.login_banner_textnon_empty_strno
fedramp_moderateegress.external_llm_enabledtrueno
fedramp_moderatelabels.block_external_llmtrueno
fedramp_moderategsec.transport.internal_tls_enforceeq requireno
fedramp_moderateaccess_review.schedule_enabledtrueno
fedramp_high_il5auth.mfa_required_for_adminstrueyes
fedramp_high_il5auth.mfa_required_for_alltrueyes
fedramp_high_il5auth.phishing_resistant_onlytrueyes
fedramp_high_il5auth.x509_enabledtrueno
fedramp_high_il5auth.sso_session_idle_secondsmax 300yes
fedramp_high_il5auth.sso_session_max_lifetime_secondsmax 14400yes
fedramp_high_il5auth.inactive_disable_daysmin 35yes
fedramp_high_il5auth.lockout_max_failuresmax 3yes
fedramp_high_il5auth.lockout_window_minmax 15yes
fedramp_high_il5auth.lockout_duration_minmin 30yes
fedramp_high_il5auth.lockout_permanent_until_admintrueyes
fedramp_high_il5auth.login_banner_textnon_empty_strno
fedramp_high_il5egress.sealed_modetrueno
fedramp_high_il5egress.nim_enabledtrueno
fedramp_high_il5egress.model_download_enabledtrueno
fedramp_high_il5egress.external_llm_enabledtrueno
fedramp_high_il5labels.block_external_llmtrueno
fedramp_high_il5gsec.transport.internal_tls_enforceeq requireno
fedramp_high_il5security.stack_tokens_fail_closedtrueno
fedramp_high_il5worker.egress_proxy_modeeq enforceno
fedramp_high_il5access_review.schedule_enabledtrueno
iso27001auth.mfa_required_for_adminstrueyes
iso27001auth.mfa_required_for_alltrueyes
iso27001auth.sso_session_idle_secondsmax 900yes
iso27001auth.sso_session_max_lifetime_secondsmax 28800yes
iso27001auth.inactive_disable_daysmin 90yes
iso27001auth.login_banner_textnon_empty_strno
iso27001labels.block_external_llmtrueno
iso27001gsec.transport.internal_tls_enforceeq requireno
iso27001access_review.schedule_enabledtrueno
soc2auth.mfa_required_for_adminstrueyes
soc2auth.mfa_required_for_alltrueyes
soc2auth.sso_session_idle_secondsmax 900yes
soc2auth.sso_session_max_lifetime_secondsmax 28800yes
soc2labels.block_external_llmtrueno
soc2access_review.schedule_enabledtrueno
tpnauth.mfa_required_for_adminstrueyes
tpnauth.mfa_required_for_alltrueyes
tpnauth.login_banner_textnon_empty_strno
tpnauth.sso_session_idle_secondsmax 900yes
tpnlabels.block_external_llmtrueno
tpnaccess_review.schedule_enabledtrueno
privacyauth.mfa_required_for_adminstrueyes
privacyauth.mfa_required_for_alltrueyes
privacyauth.sso_session_idle_secondsmax 900yes
privacylabels.block_external_llmtrueno
privacyegress.external_llm_enabledtrueno
privacyprivacy.erasure_job_enabledtrueno
privacyaccess_review.schedule_enabledtrueno

When more than one profile is active, the requirement for a shared key is the stricter one (_merge_requirement: tighter max, higher min, true, non_empty_str, eq), so an install declaring cmmc and iso27001 together locks auth.inactive_disable_days at min 90.

One note to know about before relying on the map:

  • auth.session_max_concurrent (registered as SESSION_LIMIT_SETTING_KEY, int, default 0, group auth) is in the disruptive list but is not required by any profile, so it is only disruptive if a profile ever comes to require it.

Preview and apply​

The lock map is a checklist until it is applied, and applying it is an explicit, two-step, audited operation — setting the profile list never changes a setting by itself.

  1. Set the active list — PUT /v1/platform/compliance/profiles with {"profiles": ["cmmc"]} (platform admin). The response reports weaker_settings: the keys currently below what the profile requires, none of them changed by the call. GET /v1/platform/compliance/profiles (platform admin or a time-boxed auditor) shows each profile's required settings with the current value and pass/fail.
  2. Preview — POST /v1/platform/compliance/profiles/preview with {"profiles": ["cmmc"]}. Read-only: it returns exactly the settings that would change (setting, current, value), which of them are disruptive, disruptive_count, grace_days, grace_deadline and a preview_hash.
  3. Apply — POST /v1/platform/compliance/profiles/apply with {"profiles": ["cmmc"], "preview_hash": "<hash from step 2>"}. The call requires fresh re-authenticated auth, recomputes the preview from current state, and 409s (reason: stale_preview, plus would_change) if any setting or the profile list drifted since the preview — nothing is written in that case. Otherwise each previewed setting is written through the single audited settings write path, one audit row per changed setting plus a summary row.

Disruptive items are the ones that bite running users: forced MFA enrolment, shortened session bounds, lockout and inactive-disable — auth.mfa_required_for_admins, auth.mfa_required_for_all, auth.phishing_resistant_only, auth.sso_session_idle_seconds, auth.sso_session_max_lifetime_seconds, auth.inactive_disable_days, auth.lockout_max_failures, auth.lockout_permanent_until_admin, auth.session_max_concurrent. Each carries a grace deadline of compliance.disruptive_grace_days days (default 14), recorded per key in compliance.grace_deadlines and surfaced in the /profiles and /status payloads. The deadline is recorded and audited, not auto-enforced — nothing forces an enrolment at the deadline.

Weakening a locked setting is refused with 409 and an audit row naming the profile and the requirement; the same check runs on a clear_setting revert, because reverting to the registry default can be a weakening. Preview target values always meet the requirement, so a previewed write never trips the lock — only a manual PATCH /v1/platform/settings/{key} can.

Shared baseline keys​

Several keys repeat across profiles because the controls behind them are shared (enforced_mfa, session_controls, login_banner, data_labels, tls_mtls, conformance_engine, hardened_deploy). They appear in each profile table so each table stands on its own.

none — nothing declared​

The default (compliance.declared_environment = []) declares no profile. No profile lock applies, so any setting can be moved freely, and the conformance engine still runs whatever checks are registered. Nothing here means the install is secure or unsafe — it means MOD has no declared intent to compare the install against.

cmmc — CMMC 2.0​

Setting keyRecommended valueWhyVerified by
auth.mfa_required_for_adminstruePlatform admins must carry a TOTP device (IA-2 / A.9.4.3).admin_mfa_enforced
auth.mfa_required_for_alltrue for the gov/DoD buyer tierRealm-wide OTP enrollment; machine users stay exempt.no automated check yet
auth.login_banner_textnon-empty authorized-use textAC-8 use notification on the login page.no automated check yet
auth.sso_session_idle_seconds900AC-11: end an idle session after 15 minutes.no automated check yet
auth.sso_session_max_lifetime_seconds28800AC-12: 8-hour hard session ceiling.no automated check yet
auth.access_token_lifespan_seconds900AC-12: access tokens live no more than 15 minutes.no automated check yet
auth.x509_enabledfalse (default)PIV/CAC seam is a no-op until implemented; do not expect it.no automated check yet
labels.block_external_llmtrue (default)Labelled (CUI/restricted/EAR/ITAR) content never reaches an external LLM.labels_block_external_llm
audit.chain_verify_interval_minutes60 (any positive)Scheduled HMAC audit-chain verification, no recorded break.audit_chain_verify
conformance.run_interval_minutes360 (default)Continuous conformance runs on a schedule.no automated check yet
conformance.drift_notifytrue (default)A setting flipped off shows up as a drift alert, not silence.no automated check yet

CMMC also expects keycloak_native_mfa (admins configuring MFA directly on Keycloak, available on every edition), reauth_breakglass, encryption_cmk and patch_evidence; those are install-level capabilities, not settings. The break-glass review check auth.break_glass_reviewed scores the re-auth/break-glass control and needs a recorded follow-up review for every 2FA reset in the last 30 days.

fedramp_moderate — FedRAMP-aligned Moderate​

Setting keyRecommended valueWhyVerified by
auth.mfa_required_for_adminstrueAdmin OTP enforcement (IA-2).admin_mfa_enforced
auth.login_banner_textnon-emptyAC-8 system-use banner.no automated check yet
auth.sso_session_idle_seconds900AC-11 idle termination.no automated check yet
auth.sso_session_max_lifetime_seconds28800AC-12 session ceiling.no automated check yet
auth.access_token_lifespan_seconds900AC-12 token lifetime.no automated check yet
gsec.transport.internal_tls_enforcerequireInternal hops must use TLS with the internal CA bundle (SC-8).internal_tls_enforced
audit.chain_verify_interval_minutes60AU-9 audit-chain verification scheduled.audit_chain_verify
conformance.run_interval_minutes360Scheduled conformance runs.no automated check yet
conformance.drift_notifytrueDrift is announced to admins and webhooks.no automated check yet

fedramp_high_il5 — FedRAMP-aligned High / DoD IL5​

Same auth/session and TLS keys as Moderate, plus the sealed, labelled and FIPS-facing additions below.

Setting keyRecommended valueWhyVerified by
auth.mfa_required_for_adminstrueAdmin OTP enforcement.admin_mfa_enforced
auth.mfa_required_for_alltrueHigh tier: OTP for every realm user.no automated check yet
auth.login_banner_textnon-emptyAC-8 banner.no automated check yet
auth.sso_session_idle_seconds900AC-11 idle termination.no automated check yet
auth.sso_session_max_lifetime_seconds28800AC-12 ceiling.no automated check yet
auth.access_token_lifespan_seconds900AC-12 token lifetime.no automated check yet
auth.lockout_max_failures3AC-7: lock after 3 failed sign-ins.no automated check yet
auth.lockout_window_min15AC-7: failure-count window.no automated check yet
auth.lockout_duration_min30AC-7: 30-min lockout.no automated check yet
auth.lockout_permanent_until_admintrueAC-7: only a platform admin can unlock.no automated check yet
gsec.transport.internal_tls_enforcerequireTLS enforced on internal hops.internal_tls_enforced
egress.sealed_modetrueZero outbound calls for the gated categories (SC-7).egress_sealed
labels.block_external_llmtrueLabelled data blocked from external LLMs (AC-3).labels_block_external_llm
audit.chain_verify_interval_minutes60AU-9 chain verification scheduled.audit_chain_verify
mesh.acl_enforcedtrueTailnet default-deny policy pushed on every deploy.mesh_acl_default_deny
privacy.redaction_profilestrictPII/PHI scrubbed from logs and LLM-bound text.no automated check yet
conformance.run_interval_minutes360Scheduled conformance runs.no automated check yet
conformance.drift_notifytrueDrift fan-out.no automated check yet

The fips control behind this profile is a build-level capability, not a setting — see FIPS mode at install; a stock install has no FIPS-validated crypto path today.

iso27001 — ISO/IEC 27001:2022​

ISO 27001 is the security treatment framework: it wants a documented treatment of every object, an audit trail that cannot be broken, and recovery that is proven rather than assumed. The backup keys below are the settings whose checks carry ISO control ids (A.11.2.4).

Setting keyRecommended valueWhyVerified by
auth.mfa_required_for_adminstrueA.9.4.3 operator protection for admins.admin_mfa_enforced
auth.login_banner_textnon-emptyUse notification on the login page.no automated check yet
auth.sso_session_idle_seconds900Session bound (idle).no automated check yet
auth.sso_session_max_lifetime_seconds28800Session bound (absolute).no automated check yet
auth.access_token_lifespan_seconds900Bearer-token lifetime bound.no automated check yet
audit.chain_verify_interval_minutes60A.12.4.1 / AU-9: HMAC chain verified on a schedule.audit_chain_verify
mesh.acl_enforcedtrueA.9.1.1 access-control policy on the tailnet.mesh_acl_default_deny
gsec.transport.internal_tls_enforcerequireA.9.2.3 cryptographic protection in transit.internal_tls_enforced
labels.block_external_llmtrueA.11.1.1 information scope: labelled data stays local.labels_block_external_llm
privacy.erasure_job_enabledtrueA.11.2.4 the treatment includes erasure of retired data.privacy_erasure_job
privacy.erasure_grace_days30 (default)How long after a deletion request bytes may still exist.no automated check yet
backup.rpo_target_hours24 (default)A.11.2.4 recovery point: last verified backup this fresh.backup.recent
backup.restore_test_max_age_days30 (default)A.11.2.4 a restore proof exists and is recent.backup.restore_tested
backup.rto_target_minutes240 (default)A.11.2.4 the measured recovery time is within target.backup.rto_within_target
conformance.run_interval_minutes360Continuous conformance runs.no automated check yet
conformance.drift_notifytrueDrift fan-out.no automated check yet

0 in any of the three backup.* targets disables that check (reports not-applicable) — set a real number, not zero, for this profile. See Backup and restore for how the readings are produced (backup.sh, restore-test.sh).

soc2 — SOC 2 (TSC)​

Setting keyRecommended valueWhyVerified by
auth.mfa_required_for_adminstrueOperational security: admins authenticated with OTP.admin_mfa_enforced
auth.sso_session_idle_seconds900Session bound (idle).no automated check yet
auth.sso_session_max_lifetime_seconds28800Session bound (absolute).no automated check yet
auth.access_token_lifespan_seconds900Bearer-token lifetime bound.no automated check yet
audit.chain_verify_interval_minutes60The audit trail is verified, not just written.audit_chain_verify
labels.block_external_llmtrueLabelled content never crosses to an external provider.labels_block_external_llm
gsec.transport.internal_tls_enforcerequireEncryption in transit on internal hops.internal_tls_enforced
conformance.run_interval_minutes360Continuous conformance runs.no automated check yet
conformance.drift_notifytrueDrift fan-out.no automated check yet

SOC 2 is an attestation framework: the assessable artefacts are the conformance report, the audit log and the assessor grant plus the OSCAL export at GET /v1/platform/conformance/assessment-results.oscal.json.

tpn — TPN (MPA / studio)​

The studio profile adds the delivery-side surface: a forensic watermark ID on deliveries so a leak can be traced back to the account that received it.

Setting keyRecommended valueWhyVerified by
auth.mfa_required_for_adminstrueAdmin OTP enforcement.admin_mfa_enforced
auth.login_banner_textnon-emptyUse notification on the login page.no automated check yet
auth.sso_session_idle_seconds900Session bound (idle).no automated check yet
auth.sso_session_max_lifetime_seconds28800Session bound (absolute).no automated check yet
auth.access_token_lifespan_seconds900Bearer-token lifetime bound.no automated check yet
delivery.watermark_policylabel_only or allWatermark ID on pre-release (label_only) or every (all) delivery.no automated check yet
labels.block_external_llmtrueLabelled content never reaches an external LLM.labels_block_external_llm
audit.chain_verify_interval_minutes60Audit chain verified on a schedule.audit_chain_verify
conformance.run_interval_minutes360Continuous conformance runs.no automated check yet
conformance.drift_notifytrueDrift fan-out.no automated check yet

delivery.watermark_policy is the ID-only phase: the ID is recorded on the delivery audit row and returned as the X-MOD-Watermark header; the delivered bytes are untouched. See Data labels for the pre-release tag that label_only keys off.

privacy — Privacy (GDPR / CCPA)​

Setting keyRecommended valueWhyVerified by
auth.mfa_required_for_adminstrueAdmin OTP enforcement.admin_mfa_enforced
auth.sso_session_idle_seconds900Session bound (idle).no automated check yet
auth.sso_session_max_lifetime_seconds28800Session bound (absolute).no automated check yet
auth.access_token_lifespan_seconds900Bearer-token lifetime bound.no automated check yet
privacy.erasure_job_enabledtrueThe daily erasure (crypto-shred) sweep runs.privacy_erasure_job
privacy.erasure_grace_days30 (default)Grace window before retired bytes are purged.no automated check yet
privacy.redaction_profilestandardPII scrubbed from log lines and LLM-bound text.no automated check yet
labels.block_external_llmtrueLabelled content stays away from external providers.labels_block_external_llm
audit.chain_verify_interval_minutes60Audit chain verified on a schedule.audit_chain_verify
conformance.run_interval_minutes360Continuous conformance runs.no automated check yet
conformance.drift_notifytrueDrift fan-out.no automated check yet

The erasure sweep never deletes DB rows (ISO 27001, no hard deletes) — it purges object-store bytes and destroys the tenant encryption key. BYO-S3 tenants are report-only: customer buckets are never touched.

hipaa — HIPAA​

Setting keyRecommended valueWhyVerified by
auth.mfa_required_for_adminstrueAdmin OTP enforcement.admin_mfa_enforced
auth.login_banner_textnon-emptyUse notification on the login page.no automated check yet
auth.sso_session_idle_seconds900Session bound (idle).no automated check yet
auth.sso_session_max_lifetime_seconds28800Session bound (absolute).no automated check yet
auth.access_token_lifespan_seconds900Bearer-token lifetime bound.no automated check yet
gsec.transport.internal_tls_enforcerequirePHI protected in transit on internal hops.internal_tls_enforced
privacy.redaction_profilehipaaPHI-grade redaction on logs and LLM-bound prompts.no automated check yet
labels.block_external_llmtrueLabelled PHI never reaches an external LLM.labels_block_external_llm
audit.chain_verify_interval_minutes60The audit trail (21 CFR Part 11 posture) is verified.audit_chain_verify
conformance.run_interval_minutes360Continuous conformance runs.no automated check yet
conformance.drift_notifytrueDrift fan-out.no automated check yet

privacy.redaction_profile accepts off / standard / hipaa / strict (utils/pii_redaction.PROFILES). The full PHI-redaction control on the catalog list (phi_redaction_in_logs, GY.V6) is not a product control today: the setting above covers the API log filter and the wizard LLM choke point; NodeRun inputs/outputs, task log tails and the support-chat path are follow-up work. Legal hold (GY.C15) is a paid-edition control, not a setting key.

ferpa_coppa — Education / under-13 (FERPA, COPPA)​

Setting keyRecommended valueWhyVerified by
auth.mfa_required_for_adminstrueAdmin OTP enforcement.admin_mfa_enforced
auth.login_banner_textnon-emptyUse notification on the login page.no automated check yet
auth.sso_session_idle_seconds900Session bound (idle).no automated check yet
auth.sso_session_max_lifetime_seconds28800Session bound (absolute).no automated check yet
auth.access_token_lifespan_seconds900Bearer-token lifetime bound.no automated check yet
residency.region_pinus (or the state-law region)Student records refuse to serve outside the pin.residency.stores_within_pin, residency.workers_within_pin
privacy.redaction_profilehipaaMinor/student data scrubbed from logs and LLM text.no automated check yet
labels.block_external_llmtrueLabelled student content never reaches an external LLM.labels_block_external_llm
audit.chain_verify_interval_minutes60Audit chain verified on a schedule.audit_chain_verify
conformance.run_interval_minutes360Continuous conformance runs.no automated check yet
conformance.drift_notifytrueDrift fan-out.no automated check yet

residency.region_pin accepts us, eu, or empty (off); with the pin off both residency checks report not-applicable, so set the pin for this profile. Parental consent (GY.V7) is not a product control today.

pci_dss — PCI DSS 4.0 (posture)​

Card data does not touch MOD. The profile lists what keeps that posture true.

Setting keyRecommended valueWhyVerified by
auth.mfa_required_for_adminstrueAdmin OTP enforcement.admin_mfa_enforced
auth.sso_session_idle_seconds900Session bound (idle).no automated check yet
auth.sso_session_max_lifetime_seconds28800Session bound (absolute).no automated check yet
auth.access_token_lifespan_seconds900Bearer-token lifetime bound.no automated check yet
gsec.transport.internal_tls_enforcerequireTLS on internal hops.internal_tls_enforced
privacy.redaction_profilestrictNo PII leaks into logs or LLM-bound text.no automated check yet
audit.chain_verify_interval_minutes60Audit chain verified on a schedule.audit_chain_verify
conformance.run_interval_minutes360Continuous conformance runs.no automated check yet
conformance.drift_notifytrueDrift fan-out.no automated check yet

The SAQ-A posture is scored by pci_dss_saq_a_dashboard_no_card_capture, which scans the shipped Dashboard bundle for in-app card-capture (Stripe.js Elements) code — it reads no setting key, so there is nothing to set for it.

cjis — CJIS​

Setting keyRecommended valueWhyVerified by
auth.mfa_required_for_adminstrueAdmin OTP enforcement.admin_mfa_enforced
auth.mfa_required_for_alltrueRealm-wide OTP for the state-buyer tier.no automated check yet
auth.login_banner_textnon-emptyUse notification on the login page.no automated check yet
auth.sso_session_idle_seconds900Session bound (idle).no automated check yet
auth.sso_session_max_lifetime_seconds28800Session bound (absolute).no automated check yet
auth.access_token_lifespan_seconds900Bearer-token lifetime bound.no automated check yet
auth.x509_enabledfalse (default)The PIV/CAC seam is a no-op today; do not assume PIV.no automated check yet
residency.region_pinusCJIS requires US residency; stores and workers fail closed outside it.residency.stores_within_pin, residency.workers_within_pin
gsec.transport.internal_tls_enforcerequireTLS on internal hops.internal_tls_enforced
audit.chain_verify_interval_minutes60Unforgeable audit trail (AU-9).audit_chain_verify
labels.block_external_llmtrueLabelled CJIS content never leaves to an external LLM.labels_block_external_llm
mesh.acl_enforcedtrueTailnet default-deny policy.mesh_acl_default_deny
conformance.run_interval_minutes360Continuous conformance runs.no automated check yet
conformance.drift_notifytrueDrift fan-out.no automated check yet

The fips control this profile expects is a build-level capability, not a setting — see FIPS mode at install.

iec62443_nerc — Industrial (IEC 62443 / NERC CIP adjacent)​

Setting keyRecommended valueWhyVerified by
auth.mfa_required_for_adminstrueAdmin OTP enforcement.admin_mfa_enforced
auth.sso_session_idle_seconds900Session bound (idle).no automated check yet
auth.sso_session_max_lifetime_seconds28800Session bound (absolute).no automated check yet
auth.access_token_lifespan_seconds900Bearer-token lifetime bound.no automated check yet
egress.sealed_modetrueZero outbound calls for the gated categories.egress_sealed
gsec.transport.internal_tls_enforcerequireBoundary protection on internal hops.internal_tls_enforced
audit.chain_verify_interval_minutes60Audit chain verified on a schedule.audit_chain_verify
conformance.run_interval_minutes360Continuous conformance runs.no automated check yet
conformance.drift_notifytrueDrift fan-out.no automated check yet

With egress.sealed_mode on, every per-category switch (egress.nim_enabled, egress.model_download_enabled, egress.external_llm_enabled, egress.webhooks_enabled, egress.wizard_internet_enabled, egress.license_phonehome_enabled) is treated as disabled, so there is nothing else to flip. The plant-side controls belong to the client's own systems. See IEC 62443 boundary report.

itar_ear — Export-controlled (ITAR / EAR)​

Setting keyRecommended valueWhyVerified by
compliance.export_control_enforcedtrueMaster switch: EAR/ITAR assets gated to US-person readers and US-person workers.no automated check yet
compliance.cui_requires_us_persontrue (only with the master switch on)Extend the US-person gate to CUI-classified assets.no automated check yet
compliance.itar_requires_us_residencytrue (only with the master switch on)ITAR work claimable only by a US-person-operated worker in the US zone.no automated check yet
residency.region_pinusUS-only residency for stores and workers.residency.stores_within_pin, residency.workers_within_pin
egress.sealed_modetrueNo outbound calls for the gated categories.egress_sealed
labels.block_external_llmtrueLabelled export-controlled content never reaches an external LLM.labels_block_external_llm
gsec.transport.internal_tls_enforcerequireTLS on internal hops.internal_tls_enforced
auth.mfa_required_for_adminstrueAdmin OTP enforcement.admin_mfa_enforced
auth.mfa_required_for_alltrueRealm-wide OTP.no automated check yet
auth.login_banner_textnon-emptyUse notification on the login page.no automated check yet
auth.sso_session_idle_seconds900Session bound (idle).no automated check yet
auth.sso_session_max_lifetime_seconds28800Session bound (absolute).no automated check yet
auth.access_token_lifespan_seconds900Bearer-token lifetime bound.no automated check yet
audit.chain_verify_interval_minutes60Audit chain verified on a schedule.audit_chain_verify
mesh.acl_enforcedtrueTailnet default-deny policy.mesh_acl_default_deny
conformance.run_interval_minutes360Continuous conformance runs.no automated check yet
conformance.drift_notifytrueDrift fan-out.no automated check yet

The three compliance.* keys are the export-control gate: MOD enables export-control gating; it never certifies compliance with ITAR/EAR. A worker with an unknown residency zone fails closed. The export-control taxonomy itself (export_control_tagging) is a paid-edition control, not a setting.

Setting keyRecommended valueWhyVerified by
auth.mfa_required_for_adminstrueAdmin OTP enforcement.admin_mfa_enforced
auth.sso_session_idle_seconds900Session bound (idle).no automated check yet
auth.sso_session_max_lifetime_seconds28800Session bound (absolute).no automated check yet
auth.access_token_lifespan_seconds900Bearer-token lifetime bound.no automated check yet
gsec.transport.internal_tls_enforcerequireDuty of confidentiality: TLS on internal hops.internal_tls_enforced
privacy.redaction_profilestrictClient content never appears in logs or LLM-bound text.no automated check yet
labels.block_external_llmtrueLabelled client content stays local.labels_block_external_llm
audit.chain_verify_interval_minutes60Audit chain verified on a schedule.audit_chain_verify
conformance.run_interval_minutes360Continuous conformance runs.no automated check yet
conformance.drift_notifytrueDrift fan-out.no automated check yet

The preservation duty is the legal-hold control (GY.C15, paid edition): the check legal_hold.retention_respects_holds scans the retention/purge GC paths for the fail-closed hold gate at every scope and reads no setting key.

eu_ai_act — EU AI Act (transparency + logging)​

Setting keyRecommended valueWhyVerified by
labels.block_external_llmtrueLabelled content is kept off external providers.labels_block_external_llm
audit.chain_verify_interval_minutes60The logging posture is verified, not just written.audit_chain_verify
conformance.run_interval_minutes360Continuous conformance runs.no automated check yet
conformance.drift_notifytrueDrift fan-out.no automated check yet

The transparency log itself (GY.V10) is not a product control today, so this profile has no transparency setting to point at; model documentation and impact assessments remain client-side paperwork.

Controls that are not settings​

The profile lists in ENVIRONMENT_CONTROLS mix settings and capabilities. These are capabilities or build-level items with no setting key, so nothing in the platform-settings registry toggles them: profile_locks (GY.C1), enforced_mfa (backed by auth.mfa_required_for_admins), keycloak_native_mfa, login_banner (backed by auth.login_banner_text), session_controls (backed by the four auth.* lifespan keys), reauth_breakglass, fips, encryption_cmk, tls_mtls (backed by gsec.transport.internal_tls_enforce), hardened_deploy, conformance_engine (backed by the two conformance.* keys), access_reviews, patch_evidence, sealed_mode (backed by egress.sealed_mode), data_labels (backed by labels.block_external_llm), legal_hold, data_residency_pin (backed by residency.region_pin), export_control_tagging, phi_redaction_in_logs, parental_consent, ai_transparency_log.

The available_on field in CONTROL_CATALOG says which edition provides a control; "none" means the product has no such control today, and a paid install never claims a control it does not have.