Skip to content

Security & Compliance

Evidence, not promises.

LocumView is designed to support HIPAA Security Rule technical safeguards. Hardening, identity, and audit controls are built into the platform, and the evidence for each one is versioned alongside the code.
  • Hardening approach

    Next phase: desktops hardened at build time using DISA STIG profiles for the target operating system, then scanned with OpenSCAP before any image is promoted. Not applied yet.

    • Planned: profile applied during image build
    • Planned: automated OpenSCAP scan on every build
    • Planned: documented, reviewed exceptions
  • Identity and MFA

    All access flows through Keycloak single sign-on, with MFA enforced at sign-in (TOTP today). Phishing-resistant WebAuthn and FIDO2 security keys are next.

    • Live: OIDC single sign-on; next: federation with a central directory (Red Hat IdM)
    • Live: group-based desktop assignment
    • Live: session timeouts and re-authentication
  • Audit logging

    Live: sign-ins (with source IP), administrative changes, and desktop connections are logged with who, what, and when. Next: session recording. Agent actions will be logged when agents exist.

    • Live: session start, end, and source
    • Planned: agent inputs, sources cited, and outputs
    • Planned: export to your SIEM
  • Evidence-driven change control

    Every change to the platform is a signed commit with a changelog entry and its evidence: logs, checksums, and test results. Releases with attached scan results arrive with the image pipeline.

    • Live: signed commits with automated secret scanning
    • Live: test evidence recorded in the build log
    • Rollback by snapshot today; by image next

Access path

The only way in.

A single, authenticated route from browser to desktop. Remote desktop protocols stay on the private network.
  1. User browserNo client install
  2. TLS reverse proxyTerminates HTTPS
  3. Guacamole gatewayKeycloak SSO + MFA
  4. Hardened desktopSTIG baseline
public HTTPS onlyprivate Tailscale or Cloudflare Tunnel
Remote desktop protocols stay on the private network. The dashed boundary marks components that are never reachable from the internet directly.
Access
Browser only, via Apache Guacamole
Identity
Keycloak SSO (OIDC)
MFA
TOTP enforced; WebAuthn / FIDO2 next
Transport
TLS at the edge, encrypted tunnel inward
Network
Outbound-only Cloudflare Tunnel, no open ports
RDP / VNC
Never exposed to the internet
Baseline
DISA STIG + OpenSCAP: next phase
Audit
Sign-ins and connections logged; session recording next

HIPAA mapping

Technical safeguard mapping.

How LocumView controls align with the HIPAA Security Rule technical safeguards. Evidence references will be published as validation is completed.
HIPAA Security Rule technical safeguard mapping
SafeguardLocumView controlEvidence
Access control§164.312(a)Keycloak SSO, group-based desktop access, automatic session timeoutPlaceholder
Audit controls§164.312(b)Sign-in, administrative, and connection logging (agent logging planned)Placeholder
Integrity§164.312(c)Planned: immutable, signed images; versioned knowledge basePlaceholder
Person or entity authentication§164.312(d)SSO with enforced MFA (TOTP); WebAuthn / FIDO2 nextPlaceholder
Transmission security§164.312(e)TLS at the edge and RDP over TLS; desktop protocols never public (in-cluster encryption next)Placeholder

Placeholder mapping. LocumView is designed to support these safeguards. Compliance depends on how the platform is deployed and operated.