Security Policy & Architecture
Architectural security boundaries, cryptographic key controls, database isolation, and operational posture of the Material Governance Condition (MGC) platform.
01. Security Architecture & Posture
MGC is engineered to serve as an authoritative reference monitor for mission-critical software supply chains and autonomous agentic pipelines. Security guarantees are enforced through structural and cryptographic boundaries rather than heuristic policy evaluations.
02. Hardware KMS Separation of Duties
Administrative and operational actions in MGC are partitioned across five hardware-backed cryptographic authority keys hosted in AWS Key Management Service (KMS) with FIPS 140-3 Level 3 validated Hardware Security Modules (HSMs):
- ISSUER_ROOT: Inscribes root governance conditions onto foundational datasets, repositories, and base models.
- SECURITY_RESOLUTION: Signs discharge tokens verifying security vulnerability resolution (e.g. CVE remediations).
- RISK_OWNER: Signs operational risk acceptance and time-bounded exception waivers.
- BREAK_GLASS: Emergency high-privilege override key requiring dual-custody approval and automatic immutable audit generation.
- ADJUDICATOR: Judicial key for cross-tenant dispute resolution and downstream lineage clearing.
No single master administrator credential possesses the technical ability to perform actions reserved for another typed authority.
03. Postgres Row-Level Security (RLS)
Tenant data isolation is enforced directly within the PostgreSQL engine using Row-Level Security policies. All tenant-scoped tables mandate FORCE ROW LEVEL SECURITY. The application connection role does not possess the rolbypassrls attribute, ensuring that multi-tenant isolation cannot be compromised even in the event of an application-layer logical flaw.
04. Ephemeral STS Credential Brokering
Autonomous agents and CI/CD runners interacting with MGC do not store ambient, long-lived AWS credentials. The MGC Credential Broker evaluates condition satisfaction at invocation time:
- If any blocking condition is active along the lineage path, credential issuance is denied.
- Upon successful semilattice clearance, the broker calls AWS Security Token Service (STS) to vend short-lived, least-privilege session tokens scoped strictly to the required action and expiring in minutes.
05. Model Context Protocol (MCP) Gateway Controls
MGC exposes a dedicated MCP server enabling LLM agents to evaluate lineage and conditions. The MCP gateway implements:
- Strict tenant validation and API key authentication on every tool call.
- Input validation eliminating command injection, path traversal, and malicious URN schemas.
- Deterministic error reporting preventing timing and side-channel leakage across tenant boundaries.
06. Fail-Closed Posture
In accordance with the bounded semilattice algebra, DENY is the strict zero element (⊥). If a derivation graph contains severed edges, unresolvable ancestor references, or unrecognized cryptographic signatures, the evaluation engine immediately resolves to DENY, halting downstream execution until verified.
07. Cryptographic Audit Ledger
Every state change—condition inscription, graph relationship update, authority signature verification, and emergency break-glass event—is recorded in an append-only audit log. Ledger entries include timestamps, actor identity, hardware key IDs, and SHA-256 cryptographic signatures.
08. Coordinated Vulnerability Disclosure
Cognispace, LLC welcomes responsible security research. If you believe you have discovered a vulnerability in the MGC specification or Reference Monitor, please report it directly to:
Email: security@cognispacehq.com
PGP Key: Available upon request.
We commit to acknowledging reports within 24 hours and providing regular remediation updates.