- An account of its own
- A production AWS account that holds nothing but ICM, under organization-level rules that stop it turning off audit logging or threat detection, lock out the root user, and allow only two US regions.
- Encrypted at rest and in transit
- The database, files, backups, and logs encrypted with keys held for ICM alone. TLS 1.2 or higher on every connection, including the app's own connection to its database, and AWS services reached through their FIPS endpoints.
- A database with no way in from the internet
- Isolated subnets that only the application can reach, two data centers at once, 35 days of point-in-time recovery, a separate backup copy, and protection against being deleted by accident.
- A firewall in front
- AWS WAF screening every request: known bad addresses, SQL injection, and common exploits blocked, and anything that floods the site slowed down.
- Watched around the clock
- GuardDuty threat detection across the account with alerts on anything serious, Security Hub checks against NIST SP 800-53, and network, DNS, and application logs kept for at least a year.
- A domain that is hard to fake
- cyntrixicm.com is signed with DNSSEC, only Amazon may issue its certificates, and its mail is signed so that forged messages are rejected.