The Accelerator Powered By SPITFIRE™ Workflows
SOC 1 / SOC 2 Compliance Status — Dev Environment
27/30
items complete · Backend reachable
Identity & Access
GitHub OIDC authentication (no static AWS keys)Done
Least-privileged Dev cross-account roleDone
Least-privileged Production cross-account roleDone
Management role scoped to least privilegeOpen
GitHubTerraformLandingZoneRole still has AdministratorAccess
Branch protection / required reviewsOpen
Blocked by this repo's current GitHub plan tier
Segregation of dutiesOpen
3 of 4 repo collaborators hold full admin
Network & Infrastructure
3-tier VPC with security-group isolation - DevelopmentDone
3-tier VPC with security-group isolation - ProductionDone
Default security group locked down (CIS 5.3)Done
NAT Gateway redundancy across AZsDone
Private connectivity via VPC interface/gateway endpointsDone
TLS termination via ACM + Application Load Balancer - DevelopmentDone
TLS termination via ACM + Application Load Balancer - ProductionDone
Change Management
Persisted, lock-protected Terraform stateDone
Service Control Policies - Development OUDone
Service Control Policies - Production OUDone
Production account nested in its OUDone
GitHub Actions pinned / restricted to an allow-listDone
Configuration drift resolvedDone
Logging & Monitoring
VPC Flow Logs - DevelopmentDone
VPC Flow Logs - ProductionDone
CloudTrail - DevelopmentDone
CloudTrail - ProductionDone
AWS Config - DevelopmentDone
AWS Config - ProductionDone
GuardDuty - DevelopmentDone
GuardDuty - ProductionDone
Governance
CODEOWNERSDone
SECURITY.mdDone
.gitignoreDone