UM-SA-001 · Revision 4.0What we fix, and what your developers fix
We make four fixed-price fixes, one for each gap in the basics (page 21). Your developers make the code changes for the ten findings, from our pattern.
The fixes we make
| Fix | What we set up | Calendar time |
|---|---|---|
| Sign-in securityBAS-01. MFA covers only the people who deploy. | MFA enforced everywhere, with break-glass accounts. Single sign-on for your core apps. Conditional access rolled out report-only first, then enforced. | 3 to 4 weeks |
| Cloud alertsBAS-02. Cloud logs are kept, but nobody is alerted. | CloudTrail, GuardDuty and Security Hub on AWS, Microsoft Defender on Azure, or Security Command Center on Google Cloud, with alerts routed to your team. | 1 to 2 weeks |
| Tested backupsBAS-03. Nightly backups have never been restored in a test. | Backups configured with retention, and made immutable where your platform allows it. One restore test, documented. | 1 week |
| Web firewallBAS-04. Nothing filters traffic in front of the app. | A web application firewall in front of your app: count mode first, then tuning, then block. | 2 to 3 weeks |
The code changes your developers make
Grouped by the boundary each one repairs. Fernleaf’s developers estimate 4 to 6 weeks for all five.
| Work package | Findings | What changes | How you know it worked |
|---|---|---|---|
| Customer data isolation | ARC-01APP-01AI-01 | The account is taken from the signed-in session for every request, export job and search. No field the caller controls can widen what they see. | Own-account and cross-account cases run through the screens, the API, exports and search, cached results included. |
| Roles and membership | APP-02APP-03AI-02 | Current role, current membership and a person’s verified sign-off are checked before any change or external action. | Refused cases leave nothing behind. Removals and expired sign-offs take effect on the next request. |
| Production identity | CLD-01CLD-02 | Only the production workflow can assume the production role, and it can pass on only the runtime roles on its list. | A matrix of allowed and refused subjects and roles, checked with every policy layer in place. |
| Webhook destinations | ARC-02 | An application rule for allowed destinations, backed by network egress controls. | Internal, redirected and re-resolved addresses fail from the real delivery network. |
| Release images | CLD-03 | Sign-off and deployment both use the same verified image digest. | The deployed digest matches the one signed off, and any other image is refused. |
Retest
We check each fix. One round of retesting is included.