UM-SA-001 · Revision 4.0What we fix, and what your developers fix
Two kinds of work close the gaps. We make four fixes at fixed prices. Your developers make the code changes, working from our pattern.
The fixes we make
| Fix | What we set up | Calendar time |
|---|---|---|
| IdentityMFA covers only the people who deploy. | MFA enforced everywhere, with break-glass accounts. Single sign-on for your core apps. Conditional access rolled out report-only first, then enforced. | 3 to 4 weeks |
| Cloud monitoringCloud logs are kept, but nobody is alerted. | CloudTrail, GuardDuty and Security Hub on AWS, Microsoft Defender on Azure, or Security Command Center on Google Cloud, with alerts routed to your team. | 1 to 2 weeks |
| Backups and recoveryNightly backups have never been restored in a test. | Backups configured with retention, and made immutable where your platform allows it. One restore test, documented. | 1 week |
| EdgeNothing filters traffic in front of the app. | A web application firewall in front of your app: count mode first, then tuning, then block. | 2 to 3 weeks |
The code changes your developers make
Grouped by the boundary each one repairs. Fernleaf’s developers estimate 4 to 6 weeks for all five.
| Work package | Findings | What changes | How you know it worked |
|---|---|---|---|
| Customer data isolation | ARC-01APP-01AI-01 | The account is taken from the signed-in session for every request, export job and search. No field the caller controls can widen what they see. | Own-account and cross-account cases run through the screens, the API, exports and search, cached results included. |
| Roles and membership | APP-02APP-03AI-02 | Current role, current membership and a person’s verified sign-off are checked before any change or external action. | Refused cases leave nothing behind. Removals and expired sign-offs take effect on the next request. |
| Production identity | CLD-01CLD-02 | Only the production workflow can assume the production role, and it can pass on only the runtime roles on its list. | A matrix of allowed and refused subjects and roles, checked with every policy layer in place. |
| Webhook destinations | ARC-02 | An application rule for allowed destinations, backed by network egress controls. | Internal, redirected and re-resolved addresses fail from the real delivery network. |
| Release images | CLD-03 | Sign-off and deployment both use the same verified image digest. | The deployed digest matches the one signed off, and any other image is refused. |
Retest
We check each fix. One round of retesting is included.