Security and Privacy
Token Based Authentication
Our web UIs and the following agents and profiles uses token based authentication:
https://infozone.atlassian.net/wiki/spaces/UEPE4D/pages/107422527
https://infozone.atlassian.net/wiki/spaces/UEPE4D/pages/107224832
https://infozone.atlassian.net/wiki/spaces/UEPE4D/pages/107482780
Role Based Access Control
See https://infozone.atlassian.net/wiki/spaces/UEPE4D/pages/107349725 for more information.
OIDC Identity Provider
Access control to OIDC authenticated applications is integrated in role model, see https://infozone.atlassian.net/wiki/spaces/UEPE4D/pages/107255557 for more information.
Encryption at Rest
See https://infozone.atlassian.net/wiki/spaces/UEPE4D/pages/107380798 for more information.
Encryption at Transit
The following agents and profiles use TLS:
https://infozone.atlassian.net/wiki/spaces/UEPE4D/pages/107418989
https://infozone.atlassian.net/wiki/spaces/UEPE4D/pages/107419863
https://infozone.atlassian.net/wiki/spaces/UEPE4D/pages/107421048
https://infozone.atlassian.net/wiki/spaces/UEPE4D/pages/107422527
https://infozone.atlassian.net/wiki/spaces/UEPE4D/pages/107422424
https://infozone.atlassian.net/wiki/spaces/UEPE4D/pages/107423960
https://infozone.atlassian.net/wiki/spaces/UEPE4D/pages/107480668
https://infozone.atlassian.net/wiki/spaces/UEPE4D/pages/107225977
https://infozone.atlassian.net/wiki/spaces/UEPE4D/pages/107226868
and the system interfaces use HTTPS and TLS.
Immutable images
Usage Engine is delivered as docker images that are being scanned for any potential CVEs before being made available for download.
Automated certificate management
Use of cert-manager is recommended for deployment in private cloud or AWS, but can be disabled if needed.
See https://infozone.atlassian.net/wiki/spaces/UEPE4D/pages/107217257 , https://infozone.atlassian.net/wiki/spaces/UEPE4D/pages/107217793 for more information.