Skip to content

Module security Roadmap

github-actions[bot] edited this page Sep 28, 2026 · 26 revisions

Navigation: Home > Modules

Roadmap-Hinweis: Vage Bullets ohne Akzeptanzkriterien in Checkbox-Tasks ueberfuehren. Format: - [ ] <Task> (Target: <Q/Jahr>).

Security Module Roadmap

Current Status

Production-grade security stack with transport/auth/access-control, encryption/key-management, auditing, and threat-detection components in active use.

In Progress

  • [~] Security hardening wave Phase 2+3: cryptographic assurance, policy enforcement consistency, and operational resilience (Target: Q4 2026)
    • [~] Phase 2 Cryptography & Key Management Hardening (Target: Q4 2026)
      • Key-lifecycle validation tests: K-LIFE-01..K-LIFE-04 (tests/security/test_security_phase2_crypto_hardening_focused.cpp) (2026-08-07)
      • Crypto error-path tests: K-ERR-01..K-ERR-04 (fail-closed enforcement) (2026-08-07)
      • Key-provider failover tests: K-PROV-01..K-PROV-04 (Vault, HSM, PKI) (2026-08-07)
      • Phase 2 benchmarks: K-ROT-01..K-ROT-04 in bench_security_phase2_crypto_gates.cpp (2026-08-07)
      • Production validation: Vault/HSM/PKI hardening + failover/fail-closed matrix tests (tests/security/test_security_wavec_production_validation_focused.cpp) (2026-08-17)
    • [~] Phase 3 Policy & Data-Protection Hardening (Target: Q4 2026)
      • RLS regression tests: P-RLS-01..P-RLS-04 (tests/security/test_security_phase3_policy_hardening_focused.cpp) (2026-08-07)
      • Policy-merge tests: P-MRG-01..P-MRG-04 (deny precedence, precedence rules) (2026-08-07)
      • Deny-by-default tests: P-DENY-01..P-DENY-04 (timeout, concurrent updates) (2026-08-07)
      • Query masking tests: P-MASK-01..P-MASK-02 (PII redaction, audit trail) (2026-08-07)
      • Phase 3 benchmarks: P-MRG-01..P-MRG-05 in bench_security_phase3_policy_gates.cpp (2026-08-07)
      • Production validation: real-query-workload simulation + policy-merge/atomicity validation (tests/security/test_security_wavec_production_validation_focused.cpp) (2026-08-17)
    • [~] Phase 4a Audit Export Hardening β€” Wave C Batch 1 (Target: Q4 2026)
      • [~] High-volume stress tests for audit export reliability (Target: Q4 2026)
        • EXPORT-STRESS-01..EXPORT-STRESS-10: 10 focused stress test cases in src/security/test_audit_export_stress_focused.cpp (2026-08-18)
        • Sustained load validation: 1000+ events/sec for 5 seconds (2026-08-18)
        • Atomicity under concurrent exports: 4 threads Γ— 10 exports each (2026-08-18)
        • Idempotency with duplicate detection via bundle IDs (2026-08-18)
        • Crash-recovery checkpoint validation at 10% intervals (2026-08-18)
        • Client disconnect and recovery scenarios (2026-08-18)
        • Memory pressure graceful degradation (2026-08-18)
        • Event loss detection and reliability gates (2026-08-18)
        • Export latency p95/p99 under sustained load (2026-08-18)
        • Recovery time after disconnect: ≀2s gate (2026-08-18)
      • [~] Audit export reliability gates and metrics (Target: Q4 2026)
        • ExportMetrics struct: export_start_ms, export_end_ms, events_sent, events_confirmed, resend_count (include/security/security_evidence_collector.h) (2026-08-18)
        • export_atomicity_guarantee() method: all-or-nothing semantics (2026-08-18)
        • export_idempotency_check() method: deduplication on retry (2026-08-18)
        • lastExportMetrics() method: retrieve metrics from last export (2026-08-18)
        • Crash-recovery mechanism: checkpoint at 10% export intervals (2026-08-18)
      • [~] Export performance benchmark gates (Target: Q4 2026)
        • bench_audit_export_gates.cpp with 5 benchmarks: latency, rate, file throughput, recovery time, atomicity/idempotency checks (2026-08-18)
        • Export rate gate: β‰₯10,000 events/sec (p99) (2026-08-18)
        • Export latency gate: ≀500ms per 1000-event batch (p99) (2026-08-18)
        • Recovery time gate: ≀2s after disconnect (p99) (2026-08-18)
        • Gate manifest baseline: benchmarks/wave9/audit_export_gate_manifest.json (2026-08-18)
    • [~] Phase 4b Retrieval Policy Enforcement (Deny-by-Default Security Guardrails) (Target: Q4 2026)
      • Specification Document: src/security/RETRIEVAL_POLICY_ENFORCEMENT.md (2026-09-24 CREATED)
      • Core Security Components:
        • RetrievalPolicyEnforcer β€” tenant-isolated policy validation with multi-tenant access control
        • PolicyContextGate β€” three-stage gate (credentials validation β†’ policy fetch β†’ enforcement) with hard DENY on missing policy
        • TenantRetrievalPolicy schema for multi-tenant retrieval control
        • OTLP audit trail logging all access (tenant_id, policy_version, enforcement_result, timestamp, request_id)
      • Key Security Guarantees:
        • Tenant Isolation: Per-tenant credential and policy boundaries with zero cross-tenant leakage
        • Deny-by-Default: Missing policy β†’ hard DENY via NullRetrievalBackend (deterministic exception, never silent fallback)
        • Policy Expiration: Expired policies automatically denied without grace period
        • Audit Completeness: All retrieval access logged via OTLP with complete context trail
      • Test Coverage: 13+ security-focused tests covering tenant isolation, policy expiration, audit trail completeness
      • Acceptance Criteria:
        • 0 cross-tenant data leaks verified via isolation test suite
        • Deny-by-default semantics enforced on all control paths (no silent fallbacks)
        • OTLP audit trail logs all 6 required fields per retrieval access
        • Policy expiration enforcement validated via time-mocking tests
      • CI Gate: .github/workflows/gate-pr-rag-security.yml validates security guardrail compliance on security/RAG changes

Planned Features

Short-term (3-6 months)

  • Harden policy evaluation consistency across RBAC/ABAC/RLS enforcement paths (Target: Q4 2026)
  • Expand key-rotation and key-provider failover validation under degraded external dependencies (Target: Q4 2026)
  • Strengthen audit-evidence integrity and export reliability under high event volume (Target: Q4 2026)

Mid-term (6-12 months)

  • Advance crypto-provider hardening and migration readiness across classical and PQ modes (Target: Q1 2027)
  • Expand detection and response coverage for auth abuse and injection-style attack patterns (Target: Q1 2027)
  • Improve zero-trust policy diagnostics and deny-by-default explainability for operators (Target: Q1 2027)

Implementation Phases

Phase 1: Access and Identity Hardening

  • Freeze security module API contract β€” transport/TLS, key lifecycle, policy evaluation, audit, threat detection, error taxonomy (include/security/security_api_contract.h) (Target: Q3 2026)
  • Define explicit SecurityErrorCode taxonomy (12+ codes: CERT_VALIDATION_FAILED, KEY_NOT_FOUND, KEY_ROTATION_IN_PROGRESS, POLICY_DENY, AUDIT_WRITE_FAILED, THREAT_DETECTED, ACCESS_DENIED, ENCRYPTION_FAILED, …) (Target: Q3 2026)
  • Re-validate authentication/session/control paths for fail-closed behavior under edge cases (Target: Q3 2026)
  • Strengthen token/session invalidation and revocation guarantees (Target: Q3 2026)

Phase 2: Cryptography and Key Management Hardening

  • [~] Expand key lifecycle validation (create/rotate/revoke/recover) across providers (Target: Q4 2026)
    • Key-lifecycle tests K-LIFE-01..K-LIFE-04 (2026-08-07)
    • Key-provider benchmarks K-ROT-01..K-ROT-04 (2026-08-07)
    • Vault provider production-config and fail-closed validation (tests/security/test_security_wavec_production_validation_focused.cpp) (2026-08-17)
    • HSM provider production-mode/stub-guard validation (tests/security/test_security_wavec_production_validation_focused.cpp) (2026-08-17)
    • PKI-oriented fail-closed dependency validation (matrix coverage) (tests/security/test_security_wavec_production_validation_focused.cpp) (2026-08-17)
  • [~] Tighten crypto error-path handling and secure-default enforcement (Target: Q4 2026)
    • Crypto error-path tests K-ERR-01..K-ERR-04 (2026-08-07)
    • Key-provider failover tests K-PROV-01..K-PROV-04 (2026-08-07)
    • Production failure-injection matrix validation (tests/security/test_security_wavec_production_validation_focused.cpp) (2026-08-17)
    • Fix TimestampAuthority::generateNonce() β€” replaced sequential-byte counter with RAND_bytes (cryptographic security gap, wave1 gap-closure 2026-08-31)
    • Add fail-closed guard to hsm_provider_pkcs11.cpp getCertificate() fallback β€” stub PEM now requires THEMIS_ALLOW_HSM_STUB=1 opt-in (wave1 gap-closure 2026-08-31)
    • Add STUB/SIMULATION NOTE template to HSMKeyProviderAdapter injectable DEK bridge (#47/#48) (wave1 gap-closure 2026-08-31)
    • Add STUB/SIMULATION NOTE template + per-call WARN to hsm_provider_pkcs11.cpp fallback sign path (wave1 gap-closure 2026-08-31)
    • Add STUB/SIMULATION NOTE template + WARN to HSMPKIClient::getCertSerial() silent stub (wave1 gap-closure 2026-08-31)
  • [I] PKCS#11 real HSM signing integration (hsm_provider_pkcs11.cpp β€” stub sign path active when real_ready==false) (Target: Wave 2 / Q1 2027)
  • [I] RFC 3161 / eIDAS qualified timestamp implementation (timestamp_authority_openssl.cpp β€” requires -DTHEMIS_USE_OPENSSL_TSA=ON + libcurl) (Target: Wave 2 / Q1 2027)

Phase 3: Policy and Data-Protection Hardening

  • [~] Expand RLS/masking/policy-enforcement regression coverage under mixed query workloads (Target: Q4 2026)
    • RLS tests P-RLS-01..P-RLS-04 (2026-08-07)
    • Query masking tests P-MASK-01..P-MASK-02 (2026-08-07)
    • Policy benchmarks P-MRG-01..P-MRG-05 (2026-08-07)
    • Real query workload testing (tests/security/test_security_wavec_production_validation_focused.cpp) (2026-08-17)
    • Mixed RLS+ABAC scenarios (tests/security/test_security_wavec_production_validation_focused.cpp) (2026-08-17)
  • [~] Validate deny-by-default and policy-merge semantics under conflicting rule sets (Target: Q4 2026)
    • Policy-merge tests P-MRG-01..P-MRG-04 (2026-08-07)
    • Deny-by-default tests P-DENY-01..P-DENY-04 (2026-08-07)
    • Conflict resolution edge case validation (tests/security/test_security_wavec_production_validation_focused.cpp) (2026-08-17)
    • Concurrent policy update atomicity (tests/security/test_security_wavec_production_validation_focused.cpp) (2026-08-17)

Phase 4: Threat Detection and Audit Hardening

  • Contract-hardening focused tests SEC-01..SEC-16 covering TLS/cert, key management, policy evaluation, and audit invariants (tests/security/test_security_contract_hardening_focused.cpp) (Target: Q1 2027)
  • Re-baseline detection latency and false-positive controls for security signal paths (Target: Q1 2027)
  • Ensure tamper-evidence and audit export behavior remains bounded and reliable at scale (Target: Q1 2027)

Phase 5: Documentation and Release Readiness

  • Lock benchmark-backed release gates for security hot paths: SRG-01..SRG-06 in benchmarks/security/bench_security_release_gates.cpp (policy eval p99≀1ms, JWT p99≀500Β΅s, key lookup p99≀100Β΅s, audit write p99≀500Β΅s, RBAC p99≀200Β΅s, cert validation p99≀2ms) (Target: Q3 2026)
  • Keep security docs source-aligned with explicit sourcecode verification evidence per cycle (Target: ongoing)
  • Keep completed roadmap items exclusively in changelog (Target: ongoing)

Production Readiness Checklist

  • Tracking in progress
  • Contract header frozen: include/security/security_api_contract.h (Phase 1)
  • Contract-hardening tests: tests/security/test_security_contract_hardening_focused.cpp (Phase 4, SEC-01..SEC-16)
  • Release-gate benchmarks: benchmarks/security/bench_security_release_gates.cpp (Phase 5, SRG-01..SRG-06)
  • [~] Phase 2 crypto hardening: key-lifecycle + error-path + failover tests + benchmarks (K-LIFE, K-ERR, K-PROV, K-ROT gates) (Target: Q4 2026)
    • Tests: test_security_phase2_crypto_hardening_focused.cpp (2026-08-07)
    • Benchmarks: bench_security_phase2_crypto_gates.cpp (2026-08-07)
    • Production integration validation (tests/security/test_security_wavec_production_validation_focused.cpp) (2026-08-17)
  • [~] Phase 3 policy hardening: RLS + policy-merge + deny-by-default + masking tests + benchmarks (P-RLS, P-MRG, P-DENY, P-MASK gates) (Target: Q4 2026)
    • Tests: test_security_phase3_policy_hardening_focused.cpp (2026-08-07)
    • Benchmarks: bench_security_phase3_policy_gates.cpp (2026-08-07)
    • Production integration validation (tests/security/test_security_wavec_production_validation_focused.cpp) (2026-08-17)
  • [~] Phase 4a audit export hardening: high-volume stress tests + reliability gates + benchmarks (EXPORT-STRESS-01..10, E-ATOMIC, E-IDEM, E-LATENCY gates) (Target: Q4 2026)
    • Tests: test_audit_export_stress_focused.cpp with 10 focused stress cases (2026-08-18)
    • Benchmarks: bench_audit_export_gates.cpp with export rate/latency/recovery gates (2026-08-18)
    • Metrics implementation: ExportMetrics + reliability gate methods (2026-08-18)
    • Gate baseline: benchmarks/wave9/audit_export_gate_manifest.json (2026-08-18)
  • Benchmark CMakeLists registered: benchmarks/security/CMakeLists.txt
  • Nachweise: security focused tests, auth/policy regressions, crypto/key-provider tests, security benchmarks, audit export stress/gates (Phase 1-4a)
  • Hinweis: Abgeschlossene Arbeit wird ausschliesslich in CHANGELOG dokumentiert.

Known Issues and Limitations

  • Some high-assurance runtime envelopes still require broader benchmark and regression evidence.
  • Certain external dependency failure combinations need additional hardening validation.
  • Policy explainability and operator-facing diagnostics continue to be refined.

Breaking Changes

  • Security public APIs in active major lines remain additive-first.
  • Any behavior change requiring migration must be versioned and documented in changelog/migration notes.

Program Execution Model β€” Wave Context

This module is scoped to Wave C β€” Security Production Validation in the program-level wave model. Wave C begins only after Wave B exit criteria are met. See ../../ROADMAP.md for the full Wave A β†’ B β†’ C β†’ D gate model and exit criteria.

Wave C Scope for security

  • Security: complete Vault/HSM/PKI integration validation, provider failover, real RLS/query workloads, concurrent policy updates, and policy-conflict edge cases (tests/security/test_security_wavec_production_validation_focused.cpp) (Target: Q4 2026, done: 2026-08-17)

Wave C Entry Gate (prerequisite from Wave B)

  • Wave B gate is closed: retrieval chain baselines stable, ACM observability gates closed, hardware baselines confirmed (Target: Q4 2026)

Wave C Exit Criteria (this module's contribution)

  • Production-style security integration evidence complete (tests/security/test_security_wavec_production_validation_focused.cpp) (Target: Q4 2026, done: 2026-08-17)
  • Integrity and reliability verified under sustained load (tests/security/test_security_wavec_production_validation_focused.cpp) (Target: Q4 2026, done: 2026-08-17)
  • Policy gates consistently block boundary/license/hash/SBOM regressions (tests/security/test_security_wavec_production_validation_focused.cpp) (Target: Q4 2026, done: 2026-08-17)

Dependencies on Later Waves

  • Wave D operability hardening depends on stable Wave C security controls.

ThemisDB 1.9.0-beta Β· Home Β· Module-Index Β· GitHub Β· Issues

ThemisDB Wiki

🏠 Overview

πŸ“š Compendium

πŸš€ Getting Started

πŸ“– Tutorials

πŸ“— User Guide

βš™οΈ Operations & Security

πŸ“Ÿ Ops Runbooks

πŸ—οΈ Architecture

πŸ“ ADRs

πŸ”§ Contributing

πŸ“‹ Governance

πŸ” Audit

🧩 Plugins

πŸ”Œ Adapters

πŸ’‘ Examples

πŸ“¦ Client SDKs

πŸŽ“ Training

πŸ› οΈ Tools

πŸ€– Developer LLM Wiki

Clone this wiki locally