This standard applies to all projects and shared services. It defines required controls; it does not certify that every system has already passed them.
Verify caller identity before authorizing privileged work. Bind human and machine identities to explicit roles, projects, operations, and environments. A project lease or an actor name is a coordination record, not authentication. Use expiring, revocable credentials and an authenticated recovery path.
Enforce membership, ownership, and role restrictions at the data boundary. Grant internal worker functions only to trusted workers. Review views and privileged functions as well as row-level policies. Keep production sessions and trusted origins narrow; isolate test and demo identities and data.
Validate outbound destinations and redirects, and enforce network, time, size, concurrency, and spending limits. Reserve billable resources before work. Derive attribution from verified context. Verify competitive game results on the server.
Patch dependencies, pin build inputs, preserve release evidence, and test restore procedures. Validate each change with a focused denial case and a legitimate-use case. Verify the deployed result before marking a finding closed.
Maintain a private per-project finding register with owner, severity, affected environment, remediation, deployment reference, validation evidence, and residual risk. Public pages contain standards only, never detailed vulnerability reports or private records. Track states as planned, implemented, verified, or blocked. Work available leases first and revisit occupied leases last. Do not treat untested areas as secure.