Security baseline · 安全基线

Security Statement
安全说明

Wangcai · Jarvis is a private internal application. Production self-authorization remains disabled until required application access controls and credential protections are verified.

Access control / 访问控制

Administrative server access uses SSH keys rather than passwords and is restricted to an approved source address. Application production authorization will not be enabled until role-based access control and MFA requirements are implemented and verified. Authorization credentials must not be stored in source code or client-facing pages.

服务器管理访问使用 SSH 密钥而非密码,并限制为批准的来源地址。在基于角色的访问控制和 MFA 要求实施并验证前,不启用应用生产授权。授权凭证不得存入源代码或面向用户的页面。

Network protection / 网络保护

Cloud security-group and host firewall rules expose only HTTPS/HTTP and restrict SSH to an approved administrative address. SSH intrusion prevention, malware scanning and security audit logging are enabled. The application and its future data services use a dedicated cloud environment separated from the company's other deployments.

云安全组和主机防火墙仅公开 HTTPS/HTTP,SSH 仅允许批准的管理地址访问。系统已启用 SSH 入侵防护、恶意软件扫描和安全审计日志。本应用及其后续数据服务使用独立云环境,与公司其他部署隔离。

Data protection / 数据保护

Production connections require encrypted transport. Application databases and caches are designed for private service-network access and are not intended to be directly exposed to the public internet. Data access is logged where appropriate for operational security and troubleshooting.

生产连接要求加密传输。应用数据库与缓存通过私有服务网络访问,不直接暴露到公网;必要的访问记录用于安全运营和故障排查。

Secure operations / 安全运维

Automatic operating-system security updates, daily malware scans, SSH intrusion monitoring and audit logging are enabled. Security incidents involving Amazon information are escalated under the incident-response procedure, including notification to security@amazon.com within 24 hours when required.

系统已启用操作系统自动安全更新、每日恶意软件扫描、SSH 入侵监控和审计日志。涉及 Amazon 信息的安全事件按事件响应程序升级处理,并在 Amazon 规定适用时于 24 小时内通知 security@amazon.com。

Report a security concern / 报告安全问题

Email wwy1211w08w@163.com with the subject “Security Report”. Do not include passwords, access tokens or other secrets.

请以“Security Report”为主题发送邮件,且不要在邮件中包含密码、访问令牌或其他机密信息。