Dedicated identities
Web, API, scanner, and remediator services use separate Cloud Run identities.
TrustFix is designed as security infrastructure: separated identities, tenant-scoped records, authenticated access, approval gates, drift checks, and proof after every change.
Web, API, scanner, and remediator services use separate Cloud Run identities.
The scanner is read-oriented. Storage mutation is scoped to the disposable demo bucket.
Google IAP authenticates users; backend role checks enforce Owner, Admin, Reviewer, and Viewer permissions.
Sensitive changes require an approval record and idempotency key. Unexpected drift aborts execution.
A control becomes verified only after the measurable property passes again.
Automatic observationStorage IAM, Cloud Run IAM, and internet-exposed administrative firewall ports.
Live governed mutationPublic-access removal for the explicitly named disposable TrustFix bucket.
Approval-only planningCloud Run and firewall findings remain inspectable, but mutation executors stay disabled until dedicated rollback acceptance tests pass.
Never claimedDrive, Gmail, Slack, HR, training, and policy-document evidence without a connected source.