Skip to GTOS content

Security Governance

Security Gate

Enterprise security, RBAC, evidence integrity and compliance controls for the YONGYEOKYO Global Trade Operating System.

Security Headers

ENFORCED
HeaderValuePurposeStatus
Content-Security-Policydefault-src self; frame-ancestors none; object-src nonePrevents script/object/frame injection surfacesenforced
Strict-Transport-Securitymax-age=31536000; includeSubDomains; preloadRequires HTTPS transport in productionenforced
X-Frame-OptionsDENYBlocks clickjacking fallback for legacy clientsenforced
X-Content-Type-OptionsnosniffPrevents MIME sniffingenforced
Referrer-Policystrict-origin-when-cross-originLimits cross-origin referrer leakageenforced
Permissions-Policycamera=(), microphone=(), geolocation=()Blocks unused browser capabilitiesenforced
Cross-Origin-Opener-Policysame-originHardens browsing context isolationenforced
Cross-Origin-Resource-Policysame-originRestricts cross-origin resource reuseenforced

RBAC / ABAC Roles

ROLE-GATED
RolePermissionsScopeStatus
Administratorread/write/approve/audit/legal/vault/rfq/config/analytics/docsFull governance roleenforced
Compliance Officerread/approve/audit/legal/vaultTrust, Vault and controlled approval roleenforced
Auditorread/audit/legal/vaultEvidence and audit review roleenforced
Operatorread/write/rfqOperations and controlled RFQ roleenforced
Buyerread/rfq/docsBuyer workspace and documentation request roleenforced
Supplierread/rfq/docsSupplier evidence and RFQ response roleenforced
Investorread/analyticsRead-only intelligence roleenforced

Security acceptance matrix

LayerControlPlacementPurposeStatus
HeaderContent-Security-Policydefault-src self; frame-ancestors none; object-src nonePrevents script/object/frame injection surfacesenforced
HeaderStrict-Transport-Securitymax-age=31536000; includeSubDomains; preloadRequires HTTPS transport in productionenforced
HeaderX-Frame-OptionsDENYBlocks clickjacking fallback for legacy clientsenforced
HeaderX-Content-Type-OptionsnosniffPrevents MIME sniffingenforced
HeaderReferrer-Policystrict-origin-when-cross-originLimits cross-origin referrer leakageenforced
HeaderPermissions-Policycamera=(), microphone=(), geolocation=()Blocks unused browser capabilitiesenforced
HeaderCross-Origin-Opener-Policysame-originHardens browsing context isolationenforced
HeaderCross-Origin-Resource-Policysame-originRestricts cross-origin resource reuseenforced
APIRFQ APIPOST /api/rfqRequires x-yong-role with rfq permissionenforced
APIAudit APIPOST /api/auditRequires x-yong-role with audit permissionenforced
APISearch APIGET /api/searchValidated query contract and role-aware search envelopecontrolled
APITrust APIGET /api/trustRead-only compliance and verification surfacecontrolled
APIHealth APIGET /api/healthSafe deterministic status payload for platform probescontrolled
APIReadiness APIGET /api/readinessRuntime readiness payload for deployment checkscontrolled
ComplianceNo public offerLegal disclosure footer and RFQ-gate copyCommercial risk controlenforced
ComplianceExport-control reviewLegal center + material legal disclosureStrategic material screeningenforced
ComplianceEvidence hashinglib/server/audit.ts SHA-256 evidence hashAudit integrity baselineenforced
ComplianceVendor-neutral SDS/MSDSVault evidence packageSupplier/recredentialing risk controlenforced
ComplianceProduction boundaryExternal Docker/CI/E2E/deployment evidence remains requiredReadiness honesty controlexternal-required

Production security boundary

EXTERNAL EVIDENCE REQUIRED

Application-side security gates are enforced in this repository. Full Production Ready still requires security verification from the live deployment URL and external Docker/CI/E2E evidence.

  • External Docker build evidence
  • CI runner logs
  • Browser E2E on unrestricted runner
  • Live deployment smoke test
  • Security headers verified from production URL
  • TLS certificate and HSTS verified on production domain