Skip to content

docs(readme): add Security & Compliance posture section#122

Merged
telivity-otaip merged 1 commit into
mainfrom
claude/readme-security-section
Jun 17, 2026
Merged

docs(readme): add Security & Compliance posture section#122
telivity-otaip merged 1 commit into
mainfrom
claude/readme-security-section

Conversation

@telivity-otaip

Copy link
Copy Markdown
Collaborator

Renames the README's "Compliance" section to Security & Compliance and documents HAIP's built-in security posture — tenant isolation in depth (guard + data layer + FK ownership), layered Keycloak + local RBAC, per-property Connect credentials, authenticated OTA webhooks, input/transport hardening (validation, CORS allowlist, security headers, SSRF protection, rate limiting), and the fail-closed production boot check.

Framed as design/posture, not a vulnerability disclosure. Keeps the existing PCI/GDPR/tax/auth rows. Adds an honest one-line note that security is ongoing and to pair with a deployment review + Keycloak property_ids claim before production.

Docs-only.

🤖 Generated with Claude Code


Generated by Claude Code

Document HAIP's built-in security posture (tenant isolation in depth, layered
auth, Connect/OTA authentication, input/transport hardening, fail-closed prod
defaults) alongside the existing PCI/GDPR/tax compliance table. Framed as
design, not a disclosure.

https://claude.ai/code/session_01Jq85xVJDW1NpvxQrnEdFdt
@telivity-otaip telivity-otaip merged commit 5491cd5 into main Jun 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants