Skip to main content
tasmanian.cloud
← Documentation

Security Overview

Security documentation and threat models for tasmanian.cloud — covering VPS, Kubernetes, RustFS, Netbird, and core platform controls.

By
·Last updated

This section provides comprehensive security documentation for tasmanian.cloud, including threat models, security controls, and compliance information.


Security Principles

Our security approach is built on these core principles:

  1. Defense in Depth — Multiple layers of security controls
  2. Zero Trust — Never trust, always verify
  3. Least Privilege — Minimum necessary access
  4. Sovereignty by Design — Data stays in Tasmania
  5. Transparency — Open documentation of our security model

Service Threat Models

Each service has a detailed threat model following the OpenBao security model format:


Security Goals by Service

ServiceConfidentialityIntegrityAvailabilitySovereignty
VPSVM isolationSnapshot integrityHigh availability design100% Tasmanian
TemplatesContainer isolationImage verificationHigh availability design100% Tasmanian
KubernetesPod isolationGitOps verificationHigh availability design100% Tasmanian
RustFSPQ encryptionChecksum verificationDurability by design100% Tasmanian
NetbirdWireGuard encryptionPeer authenticationMesh redundancy100% Tasmanian

Common Security Controls

Encryption

LayerAlgorithmImplementation
Data in transitTLS 1.3All external and internal APIs
Data at restAES-256-GCMDatabase and storage encryption
Post-quantumKyber-768 + Dilithium-3RustFS object encryption
VPNChaCha20-Poly1305WireGuard mesh

Authentication

  • Multi-factor authentication — Required for all administrative access
  • API keys — HMAC-SHA256 signed requests with rotation
  • JWT tokens — Short-lived access tokens (15 min) with refresh
  • Hardware keys — WebAuthn/FIDO2 supported

Network Security

  • Default deny — All traffic denied unless explicitly allowed
  • Micro-segmentation — VLANs and network policies isolate workloads
  • VPN-only access — No public IPs for customer resources
  • DDoS protection — Cloudflare Magic Transit

Monitoring and Response

  • Wazuh SIEM — Real-time log aggregation and correlation
  • Tetragon — eBPF-based runtime threat detection
  • Falco — Container runtime security
  • 24/7 alerting — PagerDuty integration for critical alerts

Standards Alignment

We design our controls to align with the standards below. We are not certified against ISO 27001 or SOC 2.

StandardAlignmentScope
ISO 27001Aligned (not certified)All services
Essential 8AlignedAustralian government baseline
PCI DSSSAQ A scopePayment processing

Data Sovereignty

  • 100% Tasmanian — All data stored in Launceston, Tasmania
  • No offshore transfers — Data never leaves Australia
  • Australian jurisdiction — Subject to Australian law
  • Privacy Act alignment — Australian Privacy Principles

Vulnerability Disclosure

We welcome responsible security research.

Scope

  • *.tasmanian.cloud
  • API endpoints
  • Customer-facing infrastructure

Out of Scope

  • Social engineering attacks
  • Physical attacks on facilities
  • Third-party services (Stripe, Cloudflare, etc.)
  • Customer applications or data

Security Updates

Subscribe to security advisories: