Security and operations
Know what the example trusts
Aarchon provides software components and an integration example. The operator remains responsible for the deployment, secret handling, network security, backups, and enforcement in each application.
What each service trusts
Identity
Identity validates access tokens and checks active sessions in PostgreSQL. The API trusts the Identity response for the user's current ID and role. Protect database credentials and use TLS at the production ingress.
Policy
Policy authenticates the calling API with a server-side token and resolves role mappings from its configured principal. Treat its policy file, token, and signing key as privileged configuration.
Protected API
The API is the enforcement point. The example trusts Policy's response over its configured service connection and does not independently verify the decision's HMAC signature. Keep service-to-service traffic on HTTPS or a trusted private network.
Fail-closed behavior
- Invalid, expired, or revoked end-user credentials are rejected.
- An explicit policy denial is returned as 403 and protected data is not returned.
- Unavailable or malformed Identity/Policy responses produce a service error, not an allow.
- Applications should log operational failures without recording bearer tokens, passwords, or policy secrets.
What this does not guarantee
- No independent security assessment, regulatory certification, compliance program, or uptime SLA is provided.
- Software HMAC ledger commitments are not hardware attestation, immutable storage, or public-key signatures.
- Policy does not intercept traffic or automatically secure routes that do not call it.
- The example does not include SSO/OIDC, MFA, account recovery, or an administrative policy UI.
Use the quickstart with disposable data first. Evaluate the whole deployment against your threat model before using it for sensitive workloads.