<!-- CANARY: REQ=REQ-SEC-AUDIT-LOG-001; FEATURE="Security"; ASPECT=AuditLog; STATUS=TESTED; OWNER=security; UPDATED=2026-01-16 -->
<h2 id="security" class="position-relative d-flex align-items-center group">
<span>Security</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="security"
aria-haspopup="dialog"
aria-label="Share link: Security">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h2><div id="headingShareModal" class="heading-share-modal" role="dialog" aria-modal="true" aria-labelledby="headingShareTitle" hidden>
<div class="hsm-dialog" role="document">
<div class="hsm-header">
<h2 id="headingShareTitle" class="h6 mb-0 fw-bold">Share this section</h2>
<button type="button" class="hsm-close" aria-label="Close">
<i class="fa-solid fa-xmark"></i>
</button>
</div>
<div class="hsm-body">
<label for="headingShareInput" class="form-label small text-muted mb-1 text-uppercase fw-bold" style="font-size: 0.7rem; letter-spacing: 0.5px;">Permalink</label>
<div class="input-group mb-4 hsm-url-group">
<input id="headingShareInput" type="text" class="form-control font-monospace" readonly aria-readonly="true" style="font-size: 0.85rem;" />
<button class="btn btn-primary hsm-copy" type="button" aria-label="Copy" title="Copy">
<i class="fa-duotone fa-clipboard" aria-hidden="true"></i>
</button>
</div>
<div class="small fw-bold mb-2 text-muted text-uppercase" style="font-size: 0.7rem; letter-spacing: 0.5px;">Share via</div>
<div class="hsm-share-grid">
<a id="share-twitter" class="btn btn-outline-secondary w-100" target="_blank" rel="noopener noreferrer">
<i class="fa-brands fa-twitter me-2"></i>Twitter
</a>
<a id="share-linkedin" class="btn btn-outline-secondary w-100" target="_blank" rel="noopener noreferrer">
<i class="fa-brands fa-linkedin me-2"></i>LinkedIn
</a>
<a id="share-facebook" class="btn btn-outline-secondary w-100" target="_blank" rel="noopener noreferrer">
<i class="fa-brands fa-facebook me-2"></i>Facebook
</a>
</div>
</div>
</div>
</div>
<style>
.heading-share-modal {
position: fixed;
inset: 0;
display: flex;
justify-content: center;
align-items: center;
background: rgba(0, 0, 0, 0.6);
z-index: 1050;
padding: 1rem;
backdrop-filter: blur(4px);
-webkit-backdrop-filter: blur(4px);
}
.heading-share-modal[hidden] { display: none !important; }
.hsm-dialog {
max-width: 420px;
width: 100%;
background: var(--bs-body-bg, #fff);
color: var(--bs-body-color, #212529);
border: 1px solid var(--bs-border-color, rgba(0,0,0,0.1));
border-radius: 1rem;
box-shadow: 0 25px 50px -12px rgba(0, 0, 0, 0.25);
overflow: hidden;
animation: hsm-fade-in 0.2s ease-out;
}
@keyframes hsm-fade-in {
from { opacity: 0; transform: scale(0.95); }
to { opacity: 1; transform: scale(1); }
}
[data-bs-theme="dark"] .hsm-dialog {
background: #1e293b;
border-color: rgba(255,255,255,0.1);
color: #f8f9fa;
}
.hsm-header {
display: flex;
justify-content: space-between;
align-items: center;
padding: 1rem 1.5rem;
border-bottom: 1px solid var(--bs-border-color, rgba(0,0,0,0.1));
background: rgba(0,0,0,0.02);
}
[data-bs-theme="dark"] .hsm-header {
background: rgba(255,255,255,0.02);
border-color: rgba(255,255,255,0.1);
}
.hsm-close {
background: transparent;
border: none;
color: inherit;
opacity: 0.5;
padding: 0.25rem 0.5rem;
border-radius: 0.25rem;
font-size: 1.2rem;
line-height: 1;
transition: opacity 0.2s;
}
.hsm-close:hover {
opacity: 1;
}
.hsm-body {
padding: 1.5rem;
}
.hsm-url-group {
display: flex !important;
align-items: stretch;
}
.hsm-url-group .form-control {
flex: 1;
min-width: 0;
margin: 0;
background: var(--bs-secondary-bg, #f8f9fa);
border-color: var(--bs-border-color, #dee2e6);
border-top-right-radius: 0;
border-bottom-right-radius: 0;
height: 42px;
}
.hsm-url-group .btn {
flex: 0 0 auto;
margin: 0;
margin-left: -1px;
border-top-left-radius: 0;
border-bottom-left-radius: 0;
height: 42px;
display: flex;
align-items: center;
justify-content: center;
padding: 0 1.25rem;
z-index: 2;
}
[data-bs-theme="dark"] .hsm-url-group .form-control {
background: #0f172a;
border-color: #334155;
color: #e2e8f0;
}
.hsm-share-grid {
display: flex;
flex-direction: column;
gap: 0.5rem;
}
.hsm-share-grid .btn {
display: flex;
align-items: center;
justify-content: center;
font-size: 0.9rem;
padding: 0.6rem;
border-color: var(--bs-border-color);
width: 100%;
}
[data-bs-theme="dark"] .hsm-share-grid .btn {
color: #e2e8f0;
border-color: #475569;
}
[data-bs-theme="dark"] .hsm-share-grid .btn:hover {
background: #334155;
border-color: #cbd5e1;
}
</style>
<script>
(function(){
const modal = document.getElementById('headingShareModal');
if(!modal) return;
const input = modal.querySelector('#headingShareInput');
const copyBtn = modal.querySelector('.hsm-copy');
const twitter = modal.querySelector('#share-twitter');
const linkedin = modal.querySelector('#share-linkedin');
const facebook = modal.querySelector('#share-facebook');
const closeBtn = modal.querySelector('.hsm-close');
let lastFocus=null;
let trapBound=false;
function buildUrl(id){ return window.location.origin + window.location.pathname + '#' + id; }
function isOpen(){ return !modal.hasAttribute('hidden'); }
function hydrate(id){
const url=buildUrl(id);
input.value=url;
const enc=encodeURIComponent(url);
const text=encodeURIComponent(document.title);
if(twitter) twitter.href=`https://twitter.com/intent/tweet?url=${enc}&text=${text}`;
if(linkedin) linkedin.href=`https://www.linkedin.com/sharing/share-offsite/?url=${enc}`;
if(facebook) facebook.href=`https://www.facebook.com/sharer/sharer.php?u=${enc}`;
}
function openModal(id){
lastFocus=document.activeElement;
hydrate(id);
if(!isOpen()){
modal.removeAttribute('hidden');
}
requestAnimationFrame(()=>{ input.focus(); });
trapFocus();
}
function closeModal(){
if(!isOpen()) return;
modal.setAttribute('hidden','');
if(lastFocus && typeof lastFocus.focus==='function') lastFocus.focus();
}
function copyCurrent(){
try{ navigator.clipboard.writeText(input.value).then(()=>feedback(true),()=>fallback()); }
catch(e){ fallback(); }
}
function fallback(){ input.select(); try{ document.execCommand('copy'); feedback(true);}catch(e){ feedback(false);} }
function feedback(ok){ if(!copyBtn) return; const icon=copyBtn.querySelector('i'); if(!icon) return; const prev=copyBtn.getAttribute('data-prev')||icon.className; if(!copyBtn.getAttribute('data-prev')) copyBtn.setAttribute('data-prev',prev); icon.className= ok ? 'fa-duotone fa-clipboard-check':'fa-duotone fa-circle-exclamation'; setTimeout(()=>{ icon.className=prev; },1800); }
function handleShareClick(e){ e.preventDefault(); const btn=e.currentTarget; const id=btn.getAttribute('data-share-target'); if(id) openModal(id); }
function bindShareButtons(){
document.querySelectorAll('.h-share').forEach(btn=>{
if(!btn.dataset.hShareBound){ btn.addEventListener('click', handleShareClick); btn.dataset.hShareBound='1'; }
});
}
bindShareButtons();
if(document.readyState==='loading'){
document.addEventListener('DOMContentLoaded', bindShareButtons);
} else {
requestAnimationFrame(bindShareButtons);
}
document.addEventListener('click', function(e){
const shareBtn=e.target.closest && e.target.closest('.h-share');
if(shareBtn && !shareBtn.dataset.hShareBound){ handleShareClick.call(shareBtn, e); }
}, true);
document.addEventListener('click', e=>{
if(e.target===modal) closeModal();
if(e.target.closest && e.target.closest('.hsm-close')){ e.preventDefault(); closeModal(); }
if(copyBtn && (e.target===copyBtn || (e.target.closest && e.target.closest('.hsm-copy')))) { e.preventDefault(); copyCurrent(); }
});
document.addEventListener('keydown', e=>{ if(e.key==='Escape' && isOpen()) closeModal(); });
function trapFocus(){
if(trapBound) return;
trapBound=true;
modal.addEventListener('keydown', f=>{ if(f.key==='Tab' && isOpen()){ const focusable=[...modal.querySelectorAll('a[href],button,input,textarea,select,[tabindex]:not([tabindex="-1"])')].filter(el=>!el.hasAttribute('disabled')); if(!focusable.length) return; const first=focusable[0]; const last=focusable[focusable.length-1]; if(f.shiftKey && document.activeElement===first){ f.preventDefault(); last.focus(); } else if(!f.shiftKey && document.activeElement===last){ f.preventDefault(); first.focus(); } } });
}
if(closeBtn) closeBtn.addEventListener('click', e=>{ e.preventDefault(); closeModal(); });
})();
</script><p>Enterprise-grade security features for protecting your data at rest, in transit, and in use. Geode provides comprehensive security capabilities including encryption, authentication, authorization, and compliance features.</p>
<blockquote>
<p><strong>Current implementation status (2026-03-30)</strong></p>
<ul>
<li>Implemented today: TDE, FLE, RBAC/ABAC/RLS, audit logging, username/password auth, sessions, API keys, MFA, and mTLS</li>
<li>Planned, not implemented: LDAP/Active Directory and OAuth2/OIDC</li>
<li>Current open auth/tooling gap: local CLI auth commands do not yet delegate to a running server</li>
</ul>
</blockquote>
<h3 id="overview" class="position-relative d-flex align-items-center group">
<span>Overview</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="overview"
aria-haspopup="dialog"
aria-label="Share link: Overview">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3><p>Security is built into every layer of Geode’s architecture. From mandatory TLS 1.3 for all network connections to Transparent Data Encryption (TDE) for data at rest, Row-Level Security (RLS) for fine-grained access control, and comprehensive audit logging for compliance, Geode provides the security features enterprises require.</p>
<p>This section covers all security capabilities including encryption strategies, authentication mechanisms, authorization models, key management, password security, session management, and compliance features for GDPR, SOX, HIPAA, and PCI-DSS.</p>
<h3 id="security-architecture" class="position-relative d-flex align-items-center group">
<span>Security Architecture</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="security-architecture"
aria-haspopup="dialog"
aria-label="Share link: Security Architecture">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="defense-in-depth" class="position-relative d-flex align-items-center group">
<span>Defense in Depth</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="defense-in-depth"
aria-haspopup="dialog"
aria-label="Share link: Defense in Depth">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p>Geode implements multiple layers of security:</p>
<ol>
<li><strong>Network Security</strong>: TLS 1.3 mandatory, no plaintext connections</li>
<li><strong>Authentication</strong>: Username/password, sessions, API keys, MFA, and mTLS</li>
<li><strong>Authorization</strong>: RBAC, ABAC, and RLS for access control</li>
<li><strong>Encryption at Rest</strong>: TDE with AES-256-GCM</li>
<li><strong>Field-Level Encryption</strong>: Searchable encryption for sensitive data</li>
<li><strong>Audit Logging</strong>: Comprehensive audit trail for compliance</li>
<li><strong>Key Management</strong>: Integration with HashiCorp Vault</li>
</ol>
<h4 id="zero-trust-model" class="position-relative d-flex align-items-center group">
<span>Zero Trust Model</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="zero-trust-model"
aria-haspopup="dialog"
aria-label="Share link: Zero Trust Model">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><ul>
<li><strong>Verify Explicitly</strong>: Authenticate and authorize every request</li>
<li><strong>Least Privilege</strong>: Grant minimum required permissions</li>
<li><strong>Assume Breach</strong>: Monitor, log, and detect anomalies</li>
</ul>
<h3 id="topics-in-this-section" class="position-relative d-flex align-items-center group">
<span>Topics in This Section</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="topics-in-this-section"
aria-haspopup="dialog"
aria-label="Share link: Topics in This Section">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3><ul>
<li><strong><a
href="/docs/security/overview/"
>Security Overview</a>
</strong> - Comprehensive security architecture overview including threat model, security controls, and best practices</li>
<li><strong><a
href="/docs/security/field-level-encryption/"
>Field-Level Encryption</a>
</strong> - Searchable encryption for sensitive fields with key rotation and performance optimization</li>
<li><strong><a
href="/docs/security/kms-integration/"
>KMS Integration</a>
</strong> - Key Management Service integration with HashiCorp Vault for secure key storage and rotation</li>
<li><strong><a
href="/docs/security/password-hashing/"
>Password Hashing</a>
</strong> - Secure password storage with Argon2id, bcrypt, and PBKDF2 algorithms</li>
<li><strong><a
href="/docs/security/post-quantum-readiness/"
>Post-Quantum Readiness</a>
</strong> - Cryptographic architecture for the Post-Quantum era including forward secrecy and algorithmic choices</li>
<li><strong><a
href="/docs/security/session-management/"
>Session Management</a>
</strong> - Secure session handling including session tokens, timeout, and revocation</li>
</ul>
<h3 id="encryption" class="position-relative d-flex align-items-center group">
<span>Encryption</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="encryption"
aria-haspopup="dialog"
aria-label="Share link: Encryption">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="transparent-data-encryption-tde" class="position-relative d-flex align-items-center group">
<span>Transparent Data Encryption (TDE)</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="transparent-data-encryption-tde"
aria-haspopup="dialog"
aria-label="Share link: Transparent Data Encryption (TDE)">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p>Encrypt all data at rest with AES-256-GCM:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl"><span class="c"># geode.yaml</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="nt">security</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">tde</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">enabled</span><span class="p">:</span><span class="w"> </span><span class="kc">true</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">key_hex</span><span class="p">:</span><span class="w"> </span><span class="s1">'<32-byte-hex-key>'</span><span class="w"> </span><span class="c"># 256-bit key</span><span class="w">
</span></span></span></code></pre></div><p><strong>Features</strong>:</p>
<ul>
<li><strong>Algorithm</strong>: AES-256-GCM (authenticated encryption)</li>
<li><strong>Scope</strong>: All pages, indexes, and WAL segments</li>
<li><strong>Key Rotation</strong>: Supported with background re-encryption</li>
</ul>
<p><strong>See</strong>: <a
href="/docs/security/overview/#transparent-data-encryption"
>Security Overview</a>
</p>
<h4 id="field-level-encryption-fle" class="position-relative d-flex align-items-center group">
<span>Field-Level Encryption (FLE)</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="field-level-encryption-fle"
aria-haspopup="dialog"
aria-label="Share link: Field-Level Encryption (FLE)">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p>Encrypt specific sensitive fields:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-gql" data-lang="gql"><span class="line"><span class="cl"><span class="err">--</span><span class="w"> </span><span class="py">Create</span><span class="w"> </span><span class="py">field</span><span class="w"> </span><span class="py">with</span><span class="w"> </span><span class="py">encryption</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">CREATE</span><span class="w"> </span><span class="p">(:</span><span class="nc">Person</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">name</span><span class="p">:</span><span class="w"> </span><span class="err">'</span><span class="nc">Alice</span><span class="err">'</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">ssn</span><span class="p">:</span><span class="w"> </span><span class="nc">encrypt</span><span class="p">(</span><span class="err">'</span><span class="py">123</span><span class="err">-</span><span class="py">45</span><span class="err">-</span><span class="py">6789</span><span class="err">'</span><span class="p">,</span><span class="w"> </span><span class="err">'</span><span class="py">ssn</span><span class="err">-</span><span class="py">key</span><span class="err">'</span><span class="p">),</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">email</span><span class="p">:</span><span class="w"> </span><span class="err">'</span><span class="nc">alice</span><span class="nd">@example</span><span class="err">.</span><span class="py">com</span><span class="err">'</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">})</span><span class="err">;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="err">--</span><span class="w"> </span><span class="py">Query</span><span class="w"> </span><span class="py">encrypted</span><span class="w"> </span><span class="py">field</span><span class="w"> </span><span class="p">(</span><span class="py">searchable</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">MATCH</span><span class="w"> </span><span class="p">(</span><span class="py">p</span><span class="p">:</span><span class="nc">Person</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WHERE</span><span class="w"> </span><span class="py">decrypt</span><span class="p">(</span><span class="py">p</span><span class="err">.</span><span class="py">ssn</span><span class="p">,</span><span class="w"> </span><span class="err">'</span><span class="py">ssn</span><span class="err">-</span><span class="py">key</span><span class="err">'</span><span class="p">)</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="err">'</span><span class="py">123</span><span class="err">-</span><span class="py">45</span><span class="err">-</span><span class="py">6789</span><span class="err">'</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">RETURN</span><span class="w"> </span><span class="py">p</span><span class="err">.</span><span class="py">name</span><span class="err">;</span><span class="w">
</span></span></span></code></pre></div><p><strong>Features</strong>:</p>
<ul>
<li><strong>Searchable Encryption</strong>: Query encrypted fields</li>
<li><strong>Deterministic Encryption</strong>: Same plaintext → same ciphertext (enables equality)</li>
<li><strong>Order-Preserving Encryption</strong>: Range queries on encrypted data</li>
<li><strong>Key Rotation</strong>: Re-encrypt data with new keys</li>
</ul>
<p><strong>See</strong>: <a
href="/docs/security/field-level-encryption/"
>Field-Level Encryption</a>
</p>
<h4 id="encryption-in-transit" class="position-relative d-flex align-items-center group">
<span>Encryption in Transit</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="encryption-in-transit"
aria-haspopup="dialog"
aria-label="Share link: Encryption in Transit">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p>All network communication encrypted with TLS 1.3:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="c1"># Server with TLS certificates</span>
</span></span><span class="line"><span class="cl">geode serve <span class="se">\
</span></span></span><span class="line"><span class="cl"><span class="se"></span> --cert /etc/geode/certs/server-cert.pem <span class="se">\
</span></span></span><span class="line"><span class="cl"><span class="se"></span> --key /etc/geode/certs/server-key.pem
</span></span></code></pre></div><p><strong>Features</strong>:</p>
<ul>
<li><strong>TLS 1.3 Only</strong>: No fallback to older versions</li>
<li><strong>Strong Cipher Suites</strong>: AES-256-GCM, ChaCha20-Poly1305</li>
<li><strong>Perfect Forward Secrecy</strong>: ECDHE key exchange</li>
<li><strong>Certificate Validation</strong>: Mutual TLS supported</li>
</ul>
<h3 id="authentication" class="position-relative d-flex align-items-center group">
<span>Authentication</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="authentication"
aria-haspopup="dialog"
aria-label="Share link: Authentication">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="authentication-methods" class="position-relative d-flex align-items-center group">
<span>Authentication Methods</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="authentication-methods"
aria-haspopup="dialog"
aria-label="Share link: Authentication Methods">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Username/Password</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="c1"># Connect with credentials</span>
</span></span><span class="line"><span class="cl">geode shell --username geode --password secret
</span></span></code></pre></div><p><strong>Multi-Factor Authentication (MFA)</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl"><span class="nt">security</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">mfa</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">enabled</span><span class="p">:</span><span class="w"> </span><span class="kc">true</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">totp</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">issuer</span><span class="p">:</span><span class="w"> </span><span class="s2">"Geode"</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">digits</span><span class="p">:</span><span class="w"> </span><span class="m">6</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">period</span><span class="p">:</span><span class="w"> </span><span class="m">30</span><span class="w">
</span></span></span></code></pre></div><p><strong>API Keys</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="c1"># Generate API key</span>
</span></span><span class="line"><span class="cl">geode apikey create --user alice --name prod-app --scope query:execute
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Use API key</span>
</span></span><span class="line"><span class="cl"><span class="nb">export</span> <span class="nv">GEODE_API_KEY</span><span class="o">=</span><span class="s2">"gsk_..."</span>
</span></span><span class="line"><span class="cl">geode shell
</span></span></code></pre></div><p><strong>LDAP/Active Directory / OAuth2/OIDC</strong>:</p>
<p>These remain roadmap items, not currently implemented server features. See <a
href="/docs/security/authentication/"
>Authentication</a>
for the current-state matrix and gap references.</p>
<p><strong>See</strong>: <a
href="/docs/security/overview/#authentication"
>Security Overview</a>
</p>
<h4 id="password-security" class="position-relative d-flex align-items-center group">
<span>Password Security</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="password-security"
aria-haspopup="dialog"
aria-label="Share link: Password Security">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p>Secure password storage with Argon2id:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl"><span class="nt">security</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">password_hashing</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">algorithm</span><span class="p">:</span><span class="w"> </span><span class="s2">"argon2id"</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">argon2</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">memory</span><span class="p">:</span><span class="w"> </span><span class="m">65536</span><span class="w"> </span><span class="c"># 64 MB</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">iterations</span><span class="p">:</span><span class="w"> </span><span class="m">3</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">parallelism</span><span class="p">:</span><span class="w"> </span><span class="m">4</span><span class="w">
</span></span></span></code></pre></div><p><strong>Supported Algorithms</strong>:</p>
<ul>
<li><strong>Argon2id</strong> (recommended): Resistant to GPU/ASIC attacks</li>
<li><strong>bcrypt</strong>: Industry standard, slower but secure</li>
<li><strong>PBKDF2</strong>: NIST approved, configurable iterations</li>
</ul>
<p><strong>See</strong>: <a
href="/docs/security/password-hashing/"
>Password Hashing</a>
</p>
<h3 id="authorization" class="position-relative d-flex align-items-center group">
<span>Authorization</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="authorization"
aria-haspopup="dialog"
aria-label="Share link: Authorization">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="role-based-access-control-rbac" class="position-relative d-flex align-items-center group">
<span>Role-Based Access Control (RBAC)</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="role-based-access-control-rbac"
aria-haspopup="dialog"
aria-label="Share link: Role-Based Access Control (RBAC)">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p>Define roles with specific permissions:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-gql" data-lang="gql"><span class="line"><span class="cl"><span class="err">--</span><span class="w"> </span><span class="py">Create</span><span class="w"> </span><span class="py">role</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">CREATE</span><span class="w"> </span><span class="py">ROLE</span><span class="w"> </span><span class="py">analyst</span><span class="err">;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="err">--</span><span class="w"> </span><span class="py">Grant</span><span class="w"> </span><span class="py">permissions</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">GRANT</span><span class="w"> </span><span class="py">SELECT</span><span class="w"> </span><span class="py">ON</span><span class="w"> </span><span class="py">GRAPH</span><span class="w"> </span><span class="py">SocialNetwork</span><span class="w"> </span><span class="py">TO</span><span class="w"> </span><span class="py">analyst</span><span class="err">;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">GRANT</span><span class="w"> </span><span class="py">EXECUTE</span><span class="w"> </span><span class="py">ON</span><span class="w"> </span><span class="py">PROCEDURE</span><span class="w"> </span><span class="py">analytics</span><span class="err">.*</span><span class="w"> </span><span class="py">TO</span><span class="w"> </span><span class="py">analyst</span><span class="err">;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="err">--</span><span class="w"> </span><span class="py">Assign</span><span class="w"> </span><span class="py">role</span><span class="w"> </span><span class="py">to</span><span class="w"> </span><span class="py">user</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">GRANT</span><span class="w"> </span><span class="py">ROLE</span><span class="w"> </span><span class="py">analyst</span><span class="w"> </span><span class="py">TO</span><span class="w"> </span><span class="py">alice</span><span class="err">;</span><span class="w">
</span></span></span></code></pre></div>
<h4 id="attribute-based-access-control-abac" class="position-relative d-flex align-items-center group">
<span>Attribute-Based Access Control (ABAC)</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="attribute-based-access-control-abac"
aria-haspopup="dialog"
aria-label="Share link: Attribute-Based Access Control (ABAC)">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p>Fine-grained policies based on attributes:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-gql" data-lang="gql"><span class="line"><span class="cl"><span class="err">--</span><span class="w"> </span><span class="py">Create</span><span class="w"> </span><span class="py">ABAC</span><span class="w"> </span><span class="py">policy</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">CREATE</span><span class="w"> </span><span class="py">POLICY</span><span class="w"> </span><span class="py">data_scientist_policy</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">FOR</span><span class="w"> </span><span class="py">SELECT</span><span class="w"> </span><span class="py">ON</span><span class="w"> </span><span class="p">:</span><span class="nc">Person</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WHEN</span><span class="w"> </span><span class="py">user</span><span class="err">.</span><span class="py">department</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="err">'</span><span class="py">Data</span><span class="w"> </span><span class="py">Science</span><span class="err">'</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">AND</span><span class="w"> </span><span class="py">user</span><span class="err">.</span><span class="py">clearance_level</span><span class="w"> </span><span class="err">></span><span class="p">=</span><span class="w"> </span><span class="py">3</span><span class="err">;</span><span class="w">
</span></span></span></code></pre></div>
<h4 id="row-level-security-rls" class="position-relative d-flex align-items-center group">
<span>Row-Level Security (RLS)</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="row-level-security-rls"
aria-haspopup="dialog"
aria-label="Share link: Row-Level Security (RLS)">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p>Restrict access at the row level:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-gql" data-lang="gql"><span class="line"><span class="cl"><span class="err">--</span><span class="w"> </span><span class="py">Create</span><span class="w"> </span><span class="py">RLS</span><span class="w"> </span><span class="py">policy</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">CREATE</span><span class="w"> </span><span class="py">POLICY</span><span class="w"> </span><span class="py">customer_isolation</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">FOR</span><span class="w"> </span><span class="py">SELECT</span><span class="w"> </span><span class="py">ON</span><span class="w"> </span><span class="p">:</span><span class="nc">Order</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WHEN</span><span class="w"> </span><span class="py">current_user</span><span class="err">.</span><span class="py">customer_id</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="py">order</span><span class="err">.</span><span class="py">customer_id</span><span class="err">;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="err">--</span><span class="w"> </span><span class="py">Enable</span><span class="w"> </span><span class="py">policy</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">ENABLE</span><span class="w"> </span><span class="py">POLICY</span><span class="w"> </span><span class="py">customer_isolation</span><span class="err">;</span><span class="w">
</span></span></span></code></pre></div><p><strong>Features</strong>:</p>
<ul>
<li><strong>Transparent</strong>: Policies applied automatically to queries</li>
<li><strong>Performance</strong>: Optimized policy evaluation</li>
<li><strong>Composable</strong>: Multiple policies combine with AND logic</li>
<li><strong>Audit</strong>: Policy evaluations logged</li>
</ul>
<p><strong>See</strong>: <a
href="/docs/security/overview/#row-level-security"
>Security Overview</a>
</p>
<h3 id="key-management" class="position-relative d-flex align-items-center group">
<span>Key Management</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="key-management"
aria-haspopup="dialog"
aria-label="Share link: Key Management">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="hashicorp-vault-integration" class="position-relative d-flex align-items-center group">
<span>HashiCorp Vault Integration</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="hashicorp-vault-integration"
aria-haspopup="dialog"
aria-label="Share link: HashiCorp Vault Integration">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p>Centralized key management with Vault:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl"><span class="nt">security</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">kms</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">provider</span><span class="p">:</span><span class="w"> </span><span class="s2">"vault"</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">vault</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">address</span><span class="p">:</span><span class="w"> </span><span class="s2">"https://vault.example.com:8200"</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">token</span><span class="p">:</span><span class="w"> </span><span class="s2">"${VAULT_TOKEN}"</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">mount_path</span><span class="p">:</span><span class="w"> </span><span class="s2">"secret/geode"</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">key_path</span><span class="p">:</span><span class="w"> </span><span class="s2">"tde-master-key"</span><span class="w">
</span></span></span></code></pre></div><p><strong>Features</strong>:</p>
<ul>
<li><strong>Centralized Keys</strong>: All encryption keys in Vault</li>
<li><strong>Key Rotation</strong>: Automated key rotation</li>
<li><strong>Audit</strong>: All key access logged</li>
<li><strong>High Availability</strong>: Vault’s HA capabilities</li>
</ul>
<p><strong>See</strong>: <a
href="/docs/security/kms-integration/"
>KMS Integration</a>
</p>
<h4 id="key-rotation" class="position-relative d-flex align-items-center group">
<span>Key Rotation</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="key-rotation"
aria-haspopup="dialog"
aria-label="Share link: Key Rotation">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p>Rotate encryption keys without downtime:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="c1"># Rotate TDE key</span>
</span></span><span class="line"><span class="cl">geode admin rotate-tde-key <span class="se">\
</span></span></span><span class="line"><span class="cl"><span class="se"></span> --old-key-id master-key-v1 <span class="se">\
</span></span></span><span class="line"><span class="cl"><span class="se"></span> --new-key-id master-key-v2
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Background re-encryption</span>
</span></span><span class="line"><span class="cl"><span class="c1"># Monitor progress:</span>
</span></span><span class="line"><span class="cl">geode admin rotation-status
</span></span></code></pre></div>
<h3 id="session-management" class="position-relative d-flex align-items-center group">
<span>Session Management</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="session-management"
aria-haspopup="dialog"
aria-label="Share link: Session Management">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3><p>Secure session handling:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl"><span class="nt">security</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">sessions</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">timeout</span><span class="p">:</span><span class="w"> </span><span class="m">3600</span><span class="w"> </span><span class="c"># 1 hour</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">absolute_timeout</span><span class="p">:</span><span class="w"> </span><span class="m">28800</span><span class="w"> </span><span class="c"># 8 hours</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">cookie_secure</span><span class="p">:</span><span class="w"> </span><span class="kc">true</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">cookie_httponly</span><span class="p">:</span><span class="w"> </span><span class="kc">true</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">cookie_samesite</span><span class="p">:</span><span class="w"> </span><span class="s2">"strict"</span><span class="w">
</span></span></span></code></pre></div><p><strong>Features</strong>:</p>
<ul>
<li><strong>Session Tokens</strong>: Cryptographically secure tokens</li>
<li><strong>Timeout</strong>: Idle and absolute timeout</li>
<li><strong>Revocation</strong>: Immediate session termination</li>
<li><strong>Single Sign-On</strong>: Integration with SSO providers</li>
</ul>
<p><strong>See</strong>: <a
href="/docs/security/session-management/"
>Session Management</a>
</p>
<h3 id="compliance" class="position-relative d-flex align-items-center group">
<span>Compliance</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="compliance"
aria-haspopup="dialog"
aria-label="Share link: Compliance">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="audit-logging" class="position-relative d-flex align-items-center group">
<span>Audit Logging</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="audit-logging"
aria-haspopup="dialog"
aria-label="Share link: Audit Logging">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p>Comprehensive audit trail:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl"><span class="nt">security</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">audit</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">enabled</span><span class="p">:</span><span class="w"> </span><span class="kc">true</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">log_path</span><span class="p">:</span><span class="w"> </span><span class="s2">"/var/log/geode/audit.log"</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">events</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span>- <span class="l">authentication</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span>- <span class="l">authorization</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span>- <span class="l">data_access</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span>- <span class="l">schema_changes</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span>- <span class="l">admin_actions</span><span class="w">
</span></span></span></code></pre></div><p><strong>Audit Events</strong>:</p>
<ul>
<li><strong>Authentication</strong>: Login, logout, MFA challenges</li>
<li><strong>Authorization</strong>: Permission checks, policy evaluations</li>
<li><strong>Data Access</strong>: All query executions with user context</li>
<li><strong>Schema Changes</strong>: DDL operations</li>
<li><strong>Administrative Actions</strong>: User management, policy changes</li>
</ul>
<p><strong>See</strong>: <a
href="/docs/ops/audit-logging/"
>Audit Logging</a>
</p>
<h4 id="compliance-features" class="position-relative d-flex align-items-center group">
<span>Compliance Features</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="compliance-features"
aria-haspopup="dialog"
aria-label="Share link: Compliance Features">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>GDPR Compliance</strong>:</p>
<ul>
<li>Data access logging</li>
<li>Right to erasure (DELETE operations)</li>
<li>Data portability (export features)</li>
<li>Consent tracking</li>
</ul>
<p><strong>SOX Compliance</strong>:</p>
<ul>
<li>Access controls for financial data</li>
<li>Audit trail of all data modifications</li>
<li>Separation of duties with RBAC</li>
<li>Change management tracking</li>
</ul>
<p><strong>HIPAA Compliance</strong>:</p>
<ul>
<li>Encryption at rest and in transit</li>
<li>Access controls for PHI</li>
<li>Audit logging of all PHI access</li>
<li>Breach notification support</li>
</ul>
<p><strong>PCI-DSS Compliance</strong>:</p>
<ul>
<li>Strong access controls</li>
<li>Encryption of cardholder data</li>
<li>Audit trails</li>
<li>Network segmentation support</li>
</ul>
<h3 id="best-practices" class="position-relative d-flex align-items-center group">
<span>Best Practices</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="best-practices"
aria-haspopup="dialog"
aria-label="Share link: Best Practices">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="encryption-1" class="position-relative d-flex align-items-center group">
<span>Encryption</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="encryption-1"
aria-haspopup="dialog"
aria-label="Share link: Encryption">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><ul>
<li><strong>Enable TDE</strong>: Encrypt all data at rest</li>
<li><strong>Use TLS 1.3</strong>: No plaintext connections</li>
<li><strong>Rotate Keys</strong>: Regular key rotation schedule</li>
<li><strong>Secure Key Storage</strong>: Use KMS (Vault) for keys</li>
<li><strong>Field-Level Encryption</strong>: For highly sensitive data</li>
</ul>
<h4 id="authentication-1" class="position-relative d-flex align-items-center group">
<span>Authentication</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="authentication-1"
aria-haspopup="dialog"
aria-label="Share link: Authentication">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><ul>
<li><strong>Enforce Strong Passwords</strong>: Minimum length, complexity requirements</li>
<li><strong>Enable MFA</strong>: Require MFA for administrative access</li>
<li><strong>Use API Keys</strong>: For service accounts and automation</li>
<li><strong>Integrate with LDAP/AD</strong>: Centralized user management</li>
<li><strong>Monitor Failed Logins</strong>: Alert on suspicious activity</li>
</ul>
<h4 id="authorization-1" class="position-relative d-flex align-items-center group">
<span>Authorization</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="authorization-1"
aria-haspopup="dialog"
aria-label="Share link: Authorization">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><ul>
<li><strong>Principle of Least Privilege</strong>: Grant minimum required permissions</li>
<li><strong>Use RBAC</strong>: Role-based permissions instead of user-specific</li>
<li><strong>Implement RLS</strong>: Row-level isolation for multi-tenant systems</li>
<li><strong>Regular Access Reviews</strong>: Audit and revoke unnecessary permissions</li>
<li><strong>Separate Duties</strong>: No single user with all privileges</li>
</ul>
<h4 id="monitoring" class="position-relative d-flex align-items-center group">
<span>Monitoring</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="monitoring"
aria-haspopup="dialog"
aria-label="Share link: Monitoring">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><ul>
<li><strong>Enable Audit Logging</strong>: Log all security events</li>
<li><strong>Monitor Anomalies</strong>: Alert on unusual access patterns</li>
<li><strong>Track Failed Auth</strong>: Multiple failed attempts → alert</li>
<li><strong>Review Logs</strong>: Regular security log analysis</li>
<li><strong>Compliance Reports</strong>: Generate compliance reports</li>
</ul>
<h3 id="threat-model" class="position-relative d-flex align-items-center group">
<span>Threat Model</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="threat-model"
aria-haspopup="dialog"
aria-label="Share link: Threat Model">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="threats-addressed" class="position-relative d-flex align-items-center group">
<span>Threats Addressed</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="threats-addressed"
aria-haspopup="dialog"
aria-label="Share link: Threats Addressed">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Network Attacks</strong>:</p>
<ul>
<li>✅ Man-in-the-middle: TLS 1.3</li>
<li>✅ Eavesdropping: Encryption in transit</li>
<li>✅ Replay attacks: Nonce-based authentication</li>
</ul>
<p><strong>Data Attacks</strong>:</p>
<ul>
<li>✅ Data theft: TDE, FLE</li>
<li>✅ Unauthorized access: RBAC, RLS</li>
<li>✅ SQL injection: Parameterized queries</li>
</ul>
<p><strong>Authentication Attacks</strong>:</p>
<ul>
<li>✅ Brute force: Rate limiting, account lockout</li>
<li>✅ Credential stuffing: MFA, password policies</li>
<li>✅ Session hijacking: Secure session tokens</li>
</ul>
<p><strong>Insider Threats</strong>:</p>
<ul>
<li>✅ Privilege abuse: Audit logging, RLS</li>
<li>✅ Data exfiltration: Access controls, monitoring</li>
<li>✅ Unauthorized changes: Audit trail, RBAC</li>
</ul>
<h4 id="security-controls" class="position-relative d-flex align-items-center group">
<span>Security Controls</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="security-controls"
aria-haspopup="dialog"
aria-label="Share link: Security Controls">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Preventive Controls</strong>:</p>
<ul>
<li>TLS 1.3 for all connections</li>
<li>Strong authentication with MFA</li>
<li>RBAC and RLS for authorization</li>
<li>Encryption at rest (TDE, FLE)</li>
</ul>
<p><strong>Detective Controls</strong>:</p>
<ul>
<li>Comprehensive audit logging</li>
<li>Anomaly detection</li>
<li>Failed authentication monitoring</li>
<li>Access pattern analysis</li>
</ul>
<p><strong>Corrective Controls</strong>:</p>
<ul>
<li>Session revocation</li>
<li>Account lockout</li>
<li>Policy enforcement</li>
<li>Incident response procedures</li>
</ul>
<h3 id="learn-more" class="position-relative d-flex align-items-center group">
<span>Learn More</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="learn-more"
aria-haspopup="dialog"
aria-label="Share link: Learn More">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3><ul>
<li><a
href="/docs/ops/deployment/"
>Deployment Guide</a>
- Secure production deployment</li>
<li><a
href="/docs/ops/audit-logging/"
>Audit Logging</a>
- Compliance and audit trails</li>
<li><a
href="/docs/configuration/"
>Configuration Reference</a>
- Security configuration</li>
<li><a
href="/docs/guides/troubleshooting/"
>Troubleshooting</a>
- Security issue resolution</li>
</ul>
<h3 id="security-resources" class="position-relative d-flex align-items-center group">
<span>Security Resources</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="security-resources"
aria-haspopup="dialog"
aria-label="Share link: Security Resources">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3><ul>
<li><strong>Security Advisories</strong>: Monitor for security updates</li>
<li><strong>Best Practices Guide</strong>: <a
href="/docs/security/overview/"
>Security Overview</a>
</li>
<li><strong>Compliance Documentation</strong>: Regulation-specific guides</li>
<li><strong>Security Checklist</strong>: Pre-deployment security review</li>
</ul>
<h3 id="reporting-security-issues" class="position-relative d-flex align-items-center group">
<span>Reporting Security Issues</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="reporting-security-issues"
aria-haspopup="dialog"
aria-label="Share link: Reporting Security Issues">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3><p>Found a security vulnerability?</p>
<ul>
<li><strong>Email</strong>: <a
href="mailto:
[email protected]"
>
[email protected]</a>
</li>
<li><strong>PGP Key</strong>: Available on website</li>
<li><strong>Response Time</strong>: Within 48 hours</li>
<li><strong>Disclosure</strong>: Coordinated disclosure process</li>
</ul>
<p>Do NOT report security issues on public issue trackers.</p>