CodexDominion

Command Console

Executive Suite

  • Jack Henry Pilot
  • Why CodexDominion
  • Value Center
  • Pilot Portfolio
  • Benchmarking
  • Evidence Exports
  • ROI Assumptions

Operations

  • Dashboard
  • Command

Platform

  • Workspace
  • Organization Memory
  • Evidence Graph
  • Workflow Engine
  • Integrations
  • Observability Console
  • Readiness
  • Security
  • CodexDominion 5.0
  • Modules
  • Knowledge

Solutions

  • Banking
  • Decision Record
  • System Brain
  • Action AI Review
  • Research Workspace
  • Truth Engine
  • ComplianceFlow
  • Veritaxis
  • Proof Packet

Capital & Procurement

  • GrantOps Readiness

Veteran Solutions

  • VetWealth Readiness

Governance

  • Decisions
  • Workflows
  • Policies
  • Evidence

Risk & Supply

  • Vendors
  • Procurement

Administration

  • Identity Center
  • Observability
  • Trust Center
  • Connectors
  • Users
  • Diagnostics
  • Settings

CodexDominion 5.0

AI Governance Control Plane

Meridian Financial Group

finance · enterprise

Administrator

Security Control Plane

Does CodexDominion know its own security posture? This evaluates the platform itself — deterministically, no external calls.

This is a platform-security posture for DEMO and PILOT evaluation. It does not certify production security — production requires verified session identity, a persistent database, tenant isolation, backups, and managed secrets.
Security posture is computed over the same platform that Organization Memory indexes.See evidence coverage and proof-packet blockers behind this posture in the Evidence Graph.See the governed workflows these controls run inside, in the Workflow Engine.See the read-only integration posture (no live connection, no credentials, no write-back).See security health within overall platform health in the Observability Console.

Platform Security Score

Security score 0/100 — status BLOCKED. Demo-secure: no; Pilot-secure: no; Production: blocked. 5 critical risk(s), 5 production blocker(s).

0/ 100
BLOCKED

Demo security

at risk

Pilot security

not ready

Production security

blocked

Environment

production

Export security report (Markdown)

Critical Risks

  • ⚠ [CRITICAL] Identity & session verification
  • ⚠ [HIGH] Tenant isolation
  • ⚠ [HIGH] Secrets management
  • ⚠ [HIGH] Persistent database
  • ⚠ [HIGH] Backups & recovery

Warnings

  • • API security (validation & rate limiting)

Production Blockers

  • Identity & session verification
  • Tenant isolation
  • Secrets management
  • Persistent database
  • Backups & recovery

Security Controls (15 categories)

One control per category, evaluated against the live posture.

CategoryControlSeverityStatusDetail
IDENTITYIdentity & session verificationCRITICALBLOCKEDIdentity is an unsigned mock/pilot actor — not a verified session.
ACCESS_CONTROLRole-based access controlINFO SECUREExport and approval are permission-gated via @merritt/workspace.
TENANT_ISOLATIONTenant isolationHIGHBLOCKEDPer-tenant data isolation is not yet verified.
AUDITAudit logging & chain integrityINFO SECUREDecision/audit events are recorded with verifiable chain integrity.
API_SECURITYAPI security (validation & rate limiting)MEDIUMWARNINGInputs are validated, but rate limiting is not yet enabled.
SECRETSSecrets managementHIGHBLOCKEDProduction secrets are not configured.
DATABASEPersistent databaseHIGHBLOCKEDNo persistent database — running on in-memory / seed data.
BACKUPSBackups & recoveryHIGHBLOCKEDBackups and recovery are not verified.
DEPENDENCIESDependency integrityINFO SECUREDependencies are pinned with no known vulnerabilities.
AI_SECURITYAI safety (no autonomous finalization)INFO SECUREAI never finalizes decisions; human approval is required; prompt injection is mitigated.
RESEARCH_SECURITYResearch integrityINFO SECUREResearch sources are manually captured and reviewed — no autonomous crawling.
DOCUMENT_SECURITYDocument verificationINFO SECUREDocuments are verified (Veritaxis) for completeness and trust before use.
EXPORT_SECURITYExport authorizationINFO SECUREProof-packet export requires authorization (EXPORT_PROOF_PACKET).
NETWORKNetwork / external surfaceINFO SECURENo live external providers or outbound crawling — minimal attack surface.
CONFIGURATIONConfiguration & data handlingINFO SECUREConfiguration is pinned and no real customer data is in use.

Threat Model

21 threats — likelihood × impact, mitigation status.

ThreatSeverityStatus

Broken Access Control

POSSIBLE · CRITICAL · mitigated

HIGHSECURE

Privilege Escalation

UNLIKELY · CRITICAL · OPEN

HIGHAT RISK

Prompt Injection

LIKELY · HIGH · mitigated

HIGHSECURE

Malicious Research

POSSIBLE · HIGH · mitigated

HIGHSECURE

Document Poisoning

POSSIBLE · HIGH · mitigated

HIGHSECURE

Fake Citations

POSSIBLE · MEDIUM · mitigated

MEDIUMSECURE

Unauthorized Export

POSSIBLE · HIGH · mitigated

HIGHSECURE

Tenant Leakage

POSSIBLE · CRITICAL · OPEN

HIGHAT RISK

Database Exposure

UNLIKELY · CRITICAL · OPEN

HIGHAT RISK

API Abuse

LIKELY · MEDIUM · OPEN

MEDIUMWARNING

Credential Theft

POSSIBLE · CRITICAL · OPEN

HIGHAT RISK

Secret Leakage

POSSIBLE · CRITICAL · mitigated

HIGHSECURE

Replay Attack

UNLIKELY · HIGH · OPEN

MEDIUMWARNING

Supply Chain Attack

POSSIBLE · HIGH · mitigated

HIGHSECURE

Dependency Attack

POSSIBLE · HIGH · mitigated

HIGHSECURE

Audit Tampering

UNLIKELY · HIGH · mitigated

MEDIUMSECURE

Model Hallucination

LIKELY · MEDIUM · mitigated

MEDIUMSECURE

Unauthorized AI Action

POSSIBLE · CRITICAL · mitigated

HIGHSECURE

Insider Threat

UNLIKELY · HIGH · mitigated

MEDIUMSECURE

Denial of Service

POSSIBLE · MEDIUM · OPEN

MEDIUMWARNING

Configuration Drift

POSSIBLE · MEDIUM · mitigated

MEDIUMSECURE

Policy Compliance

15 platform-security policies.

PolicyResultStatus
Verified identity required failBLOCKED
No pilot fallback in production passSECURE
RBAC required passSECURE
Audit required passSECURE
Tenant isolation required failBLOCKED
Persistent database required failBLOCKED
Backups required failBLOCKED
Secrets configured failBLOCKED
No hardcoded secrets passSECURE
Proof packet export gated passSECURE
Approval gated passSECURE
AI never finalizes decisions passSECURE
Research manually reviewed passSECURE
Truth Engine required passSECURE
Human approval required passSECURE

Route Protection Review

Deterministic evaluation only — no rate limiting is added.

RouteMethodPermissionIdentityAuditRate LimitedProd-ReadyRisk
/api/financial-governance/proof-packet/exportGETEXPORT_PROOF_PACKETyesyesnonoWARNING
/api/financial-governance/decision-record/approvePOSTAPPROVE_DECISIONyesyesnonoWARNING
/api/security/reportGET—nononoyesSECURE

Integration Posture

External-provider stance — read-only contracts only.

  • External providers disabled / config-required — 15 future, 6 config-required adapters; none live.
  • No credentials configured — 0 adapters require credentials.
  • No live write-back — 0 adapters allow write-back to core systems.

Next Actions

To move from demo/pilot toward production security.

  • • [IDENTITY] Integrate a verified session provider (Phase 5) before production.
  • • [TENANT_ISOLATION] Verify row-level / tenant scoping before storing multi-tenant data.
  • • [SECRETS] Configure secrets via the environment / a secrets manager before production.
  • • [DATABASE] Configure a persistent (non-SQLite-file) DATABASE_URL with least-privilege access.
  • • [BACKUPS] Configure automated backups and verify recovery before production.
  • • Policy 'Verified identity required': VIOLATION: Actions must be attributable to a verified, signed session.
  • • Policy 'Tenant isolation required': VIOLATION: Tenants must not be able to access each other's data.
  • • Policy 'Persistent database required': VIOLATION: Customer data requires a persistent, access-controlled store.
  • • Policy 'Backups required': VIOLATION: Backups and a tested recovery path are required.
  • • Policy 'Secrets configured': VIOLATION: Production secrets must be sourced from the environment / a vault.