Compliance Readiness

tsdevstack implements a security-first architecture across all three cloud providers. The framework enforces encryption, network isolation, zero-credential runtimes, and environment separation as non-optional defaults — not configurable afterthoughts.

This page maps the framework's built-in security controls against major compliance frameworks to help teams understand what's covered out of the box and what remains their responsibility.

Bottom line: tsdevstack provides all the technical infrastructure controls required by SOC 2, GDPR, and ISO 27001. Every technical requirement — encryption, network isolation, access control, audit logging, secrets management — is handled by the framework across all three providers. What remains is purely organizational: writing policies, conducting audits, and establishing review processes. The infrastructure is ready; the paperwork is yours.

Security Controls

Encryption

ControlGCPAWSAzure
TLS at edgeCloud CDN managed SSLCloudFront + ACM auto-renewFront Door managed TLS
TLS between edge and computeHTTPS to Cloud RunHTTPS to ALBHTTPS to Container Apps
Database encryption at restCloud SQL defaultRDS storage_encrypted = truePostgreSQL Flexible Server default
Database encryption in transitCloud SQL SSLSSL enabled (VPC-internal)PostgreSQL sslmode=require
Redis encryption at restMemorystore defaultElastiCache enabledAzure Redis default
Redis encryption in transitMemorystore TLSElastiCache TLSTLS-only on port 6380
Object storage encryptionGCS AES-256S3 SSE AES256Blob Storage default
Secrets at restSecret ManagerSecrets ManagerKey Vault

All encryption is enforced by default. There are no flags to disable it.

Network Isolation

ControlGCPAWSAzure
Virtual networkVPCVPCVNet
Subnet segmentationPrivate subnetsThree-tier (public, private, database)Three subnets (apps, database, container env)
Database accessPrivate IP onlyDatabase subnet + security groupPrivate DNS zone + VNet integration
Redis accessPrivate IP onlyPrivate subnet + security groupPrivate Endpoint
WAFCloud Armor (managed rulesets)AWS WAF (managed + custom rules)Front Door WAF (custom rules or DRS 2.1 on Premium)
WAF rate limiting1000 req/60s per IP (configurable)5000 req/5min per IP (configurable)1000 req/min per IP (configurable)
Access loggingLB backend service logs + Cloud Armor verboseALB logs (S3) + CloudFront logs (S3) + WAF logs (CloudWatch)Front Door diagnostic settings (Access, HealthProbe, WAF logs)
Origin verificationCloud Armor rulesX-Origin-Verify headerX-Azure-FDID header
Environment isolationSeparate GCP ProjectSeparate AWS AccountSeparate Azure Subscription
VPC Flow LogsEnabledEnabled (KMS-encrypted)Planned

Services never run in public subnets. Databases and caches have no public endpoints. Environment isolation is enforced by the framework — you cannot reuse credentials across environments.

Identity & Access Management

ControlGCPAWSAzure
Runtime authService Account bindingIAM Task RoleManaged Identity + RBAC (User-Assigned MI for Container Apps, System MI for App Service)
CI/CD authWorkload Identity FederationOIDC to IAM RoleFederated Identity Credentials
API authKong JWT validationKong JWT validationKong JWT validation
Per-service DB credentialsUnique DATABASE_URL per serviceUnique DATABASE_URL per serviceUnique DATABASE_URL per service
Secret scope separationService-scoped + shared fallbackService-scoped + shared fallbackService-scoped + shared fallback
Least privilege (runtime)Read-only secret accessTask role scoped to service secretsKey Vault Secrets User (read-only)

Zero credentials are stored in containers. Runtime authentication uses cloud-native identity (Service Accounts, IAM Roles, Managed Identities). CI/CD uses OIDC federation — no long-lived secrets in GitHub.

Container Security

ControlStatus
Non-root executionUSER node in all Dockerfiles
File ownership--chown=node:node for all copied files
Image scanningECR scan on push (AWS), Artifact Registry (GCP), ACR (Azure)
Multi-stage buildsBuilder and production stages separated
No secrets in imagesRuntime injection via cloud secret managers

Secrets Management

ControlStatus
Cloud-native storageGCP Secret Manager, AWS Secrets Manager, Azure Key Vault
Runtime caching5-minute TTL with automatic refresh
Metadata taggingmanaged-by, scope, secret-type, project-name
Soft-delete recoveryGCP: versioned, AWS: 7-day, Azure: 90-day
Naming isolation{project}-{scope}-{KEY} convention
Credential files gitignoredFramework enforces .gitignore rules

OWASP Compliance

The optional auth service template aligns with OWASP security guidelines across authentication, session management, and cryptographic storage:

OWASP Top 10 Coverage

OWASP Top 10MitigationComponent
A01 Broken Access ControlGlobal AuthGuard, Kong JWT validation, @Public() opt-inAuth template + nest-common
A02 Cryptographic FailuresRS256 JWT signing, bcrypt password hashing, SHA-256 token storage, CSPRNG token generationAuth template
A03 InjectionWAF with OWASP Core Rule Set (SQLi, XSS, LFI, RFI, RCE)Infrastructure (all providers)
A04 Insecure DesignBFF pattern (tokens never in browser JS), defense-in-depth (Kong + AuthGuard)Auth template + frontend
A05 Security MisconfigurationEncryption enforced by default, no flags to disable, environment isolationInfrastructure
A07 Auth FailuresTiming-safe comparison, configurable bcrypt rounds, refresh token rotationAuth template + nest-common
A08 Data Integrity FailuresAsymmetric JWT signing (RS256), JWKS key discovery, CI/CD via OIDCAuth template + infrastructure
A09 Logging & MonitoringVPC Flow Logs, WAF verbose logging, structured audit logsInfrastructure (all providers)
A10 Server-Side Request ForgeryPrivate subnets for databases/caches, no public endpoints, WAF request filteringInfrastructure (all providers)

OWASP Cheat Sheet Alignment

Cheat SheetImplementation
Authenticationbcrypt password hashing (configurable rounds), timing-safe comparison, account confirmation flow
Session ManagementHTTP-only cookies, Secure flag, SameSite=lax, short-lived access tokens, refresh token rotation
JWT SecurityRS256 (asymmetric), configurable TTL, audience/issuer validation, JWKS key discovery
Password Storagebcrypt with 12 rounds default, configurable via secret
Cryptographic StorageRefresh tokens hashed (SHA-256) before storage, CSPRNG for all token generation
Key ManagementRSA 2048-bit keys, key rotation with kid headers, cloud-native secret storage
Secrets ManagementCloud secret managers (GCP/AWS/Azure), zero-credential runtimes, no secrets in images

Note: The auth service is an optional template. Projects that use it get these controls out of the box. The infrastructure-level controls (WAF, encryption, network isolation) apply to all tsdevstack projects regardless of the auth template.

Compliance Framework Mapping

SOC 2 Type II

Trust Service CriteriaFramework Status
CC6.1 Logical access controlsRBAC, Managed Identity, JWT, per-service isolation
CC6.2 Credentials and authenticationZero-credential runtime, OIDC CI/CD
CC6.3 Access authorizationIAM roles scoped per service, environment isolation
CC6.6 Security boundariesVPC/VNet, WAF, private subnets, origin verification
CC6.7 Restrict data movementPrivate subnets for DB/Redis, no public endpoints
CC6.8 Unauthorized softwareNon-root containers, image scanning, multi-stage builds
CC7.1 Detect anomaliesVPC Flow Logs, WAF verbose logging, access logs (LB/CDN/WAF per provider), structured audit logs
CC8.1 Change managementGit-based IaC, CI/CD with OIDC, Terraform plan/apply

Every SOC 2 technical control listed above is enforced by default. The remaining requirements — formal change approval workflows, access review cadence, incident response playbooks — are organizational processes that vary by company and don't require infrastructure changes.

GDPR (Articles 25 & 32)

GDPR ArticleFramework Status
Art. 25 Privacy by designEncryption, isolation, least privilege as defaults
Art. 32(1)(a) EncryptionEncryption at rest and in transit across all providers
Art. 32(1)(b) ConfidentialityVPC isolation, WAF, per-service secrets, RBAC
Art. 32(1)(c) AvailabilityAuto-scaling, health checks, multi-AZ support
Art. 32(1)(d) TestingTerraform plan, CI/CD pipeline, image scanning

GDPR technical measures (Articles 25 and 32) are fully covered. Data subject rights (erasure, portability, consent) are application-level concerns that the framework leaves to the developer.

ISO 27001 (Annex A)

Annex A ControlFramework Status
A.8.5 Secure authenticationJWT, OIDC, Managed Identity, zero-credential runtime
A.8.9 Configuration managementTerraform IaC, git-based, reproducible
A.8.15 LoggingVPC Flow Logs, access logs (LB/CDN/WAF per provider), CloudWatch/Log Analytics
A.8.20 Network securityVPC/VNet, subnets, WAF, private endpoints
A.8.21 Web service securityTLS, WAF OWASP rules, rate limiting, CORS
A.8.24 CryptographyEncryption at rest + transit, KMS key rotation
A.8.25 Secure developmentCI/CD, image scanning, non-root containers

Every Annex A technical control listed above is enforced by default. ISO 27001 certification additionally requires the Information Security Management System (ISMS) — risk assessments, internal audits, management reviews — which is organizational, not technical. The infrastructure is already compliant.

What's Covered vs Your Responsibility

What tsdevstack provides

  • Encryption at rest and in transit enforced by default across all three providers
  • Zero-credential container runtimes (Managed Identity, IAM roles, Service Account binding)
  • OIDC-based CI/CD with no long-lived secrets
  • Network isolation with WAF, private subnets, and origin verification
  • Environment isolation enforced at the account/subscription/project level
  • Per-service secret and database credential isolation
  • Non-root containers with vulnerability scanning
  • Infrastructure as Code with full audit trail

What remains (organizational, not technical)

None of the items below require infrastructure changes — the framework has already handled the technical side. These are business processes your team defines:

  • SOC 2: Organizational policies, access review processes, incident response plan, vendor management
  • GDPR: Data processing agreements, privacy policy, consent management, data subject rights implementation (application-level)
  • ISO 27001: ISMS documentation, risk assessments, internal audits, management reviews

Cross-Provider Comparison

All three providers achieve equivalent security outcomes through provider-native services:

FeatureGCPAWSAzure
Runtime authService AccountIAM Task RoleManaged Identity + RBAC
CI/CD authWorkload Identity FederationOIDC to IAM RoleFederated Identity Credentials
Secret storeSecret ManagerSecrets ManagerKey Vault (RBAC)
WAFCloud ArmorAWS WAFFront Door WAF
Edge + CDNCloud CDN + LBCloudFront + ALBFront Door (unified)
Container scanningArtifact RegistryECR scan on pushACR scanning
Environment isolationSeparate ProjectsSeparate AccountsSeparate Subscriptions