Security & Compliance
Evidence, not promises.
Hardening approach
Next phase: desktops hardened at build time using DISA STIG profiles for the target operating system, then scanned with OpenSCAP before any image is promoted. Not applied yet.
- Planned: profile applied during image build
- Planned: automated OpenSCAP scan on every build
- Planned: documented, reviewed exceptions
Identity and MFA
All access flows through Keycloak single sign-on, with MFA enforced at sign-in (TOTP today). Phishing-resistant WebAuthn and FIDO2 security keys are next.
- Live: OIDC single sign-on; next: federation with a central directory (Red Hat IdM)
- Live: group-based desktop assignment
- Live: session timeouts and re-authentication
Audit logging
Live: sign-ins (with source IP), administrative changes, and desktop connections are logged with who, what, and when. Next: session recording. Agent actions will be logged when agents exist.
- Live: session start, end, and source
- Planned: agent inputs, sources cited, and outputs
- Planned: export to your SIEM
Evidence-driven change control
Every change to the platform is a signed commit with a changelog entry and its evidence: logs, checksums, and test results. Releases with attached scan results arrive with the image pipeline.
- Live: signed commits with automated secret scanning
- Live: test evidence recorded in the build log
- Rollback by snapshot today; by image next
Access path
The only way in.
- User browserNo client install
- TLS reverse proxyTerminates HTTPS
- Guacamole gatewayKeycloak SSO + MFA
- Hardened desktopSTIG baseline
- Access
- Browser only, via Apache Guacamole
- Identity
- Keycloak SSO (OIDC)
- MFA
- TOTP enforced; WebAuthn / FIDO2 next
- Transport
- TLS at the edge, encrypted tunnel inward
- Network
- Outbound-only Cloudflare Tunnel, no open ports
- RDP / VNC
- Never exposed to the internet
- Baseline
- DISA STIG + OpenSCAP: next phase
- Audit
- Sign-ins and connections logged; session recording next
HIPAA mapping
Technical safeguard mapping.
| Safeguard | LocumView control | Evidence |
|---|---|---|
| Access control§164.312(a) | Keycloak SSO, group-based desktop access, automatic session timeout | Placeholder |
| Audit controls§164.312(b) | Sign-in, administrative, and connection logging (agent logging planned) | Placeholder |
| Integrity§164.312(c) | Planned: immutable, signed images; versioned knowledge base | Placeholder |
| Person or entity authentication§164.312(d) | SSO with enforced MFA (TOTP); WebAuthn / FIDO2 next | Placeholder |
| Transmission security§164.312(e) | TLS at the edge and RDP over TLS; desktop protocols never public (in-cluster encryption next) | Placeholder |
Placeholder mapping. LocumView is designed to support these safeguards. Compliance depends on how the platform is deployed and operated.