Security
The security model, the credential and session lifecycle, every key and token in one place, the hardening steps, how to report a vulnerability and the compliance mapping.
- The security model explains what Straza protects, the invariants it holds and the residual risks it leaves with you.
- Credentials and sessions follows an enrolled machine through token refresh, session limits and revocation.
- Keys, certificates and tokens names every key and credential you protect, back up and rotate.
- Hardening tightens a deployment beyond the defaults, one control at a time, and pairs with TLS and exposure.
- Reporting a vulnerability says how to report a vulnerability privately and how the response runs.
- Compliance mapping maps Straza controls to ISO 27001 Annex A and NIS2 Article 21(2).
- Supply chain explains how a release is built, signed and verified.
To respond to a login or access incident, lock the person or device out with the kill-switch runbook, then read Credentials and sessions for what each lockout does.
- Known limits gives one table of each limit, its impact, today’s mitigation and the planned fix.