Tasmanian Cloud documentation
Security Overview
Security documentation for tasmanian.cloud services
This section describes security controls and encryption choices for tasmanian.cloud. It does not make a certification claim.
Security Principles
Our security approach is built on these core principles:
- Defense in Depth - Multiple layers of security controls
- Zero Trust - Never trust, always verify
- Least Privilege - Minimum necessary access
- Sovereignty by Design - Data stays in Tasmania
- Transparency - Open documentation of our security model
Encryption
Encryption Standards
| Layer | Algorithm | Implementation |
|---|---|---|
| Data in transit | TLS 1.3 | All external and internal APIs |
| Data at rest | AES-256-GCM | Database and storage encryption |
| Post-quantum | Kyber-768 + Dilithium-3 | Object storage encryption |
| VPN | ChaCha20-Poly1305 | WireGuard mesh |
Authentication
- Multi-factor authentication - Required for all administrative access
- API keys - HMAC-SHA256 signed requests with rotation
- JWT tokens - Short-lived access tokens (15 min) with refresh
- Hardware keys - WebAuthn/FIDO2 supported
Network Security
- Default deny - All traffic denied unless explicitly allowed
- Micro-segmentation - Network policies isolate workloads
- VPN-only access - No public IPs for customer resources
- DDoS protection - Cloudflare Magic Transit
Monitoring and Response
- Security logging - Log aggregation and alerting as the platform develops
- Runtime protection - eBPF-based threat detection
- Container security - Runtime monitoring for all containers
- Automated alerting - Critical alerts escalated immediately
Assurance status
Certifications
| Standard | Status | Scope |
|---|---|---|
| ISO 27001 | Not certified | No certification claim |
| SOC 2 Type II | Not certified | No certification claim |
| Essential 8 | Not certified | No alignment claim |
| PCI DSS | Not applicable to hosting | Payment provider scope is separate |
Data Sovereignty
- 100% Tasmanian - All data stored in Launceston, Tasmania
- No offshore transfers - Data never leaves Australia
- Australian jurisdiction - Subject to Australian law
- Australian jurisdiction - Subject to Australian law
Vulnerability Disclosure
We welcome responsible security research.
- Contact: security@tasmanian.cloud
- PGP Key: Download
- Acknowledgment: We review reports as soon as practical
Note: We do not offer financial rewards for vulnerability reports.
Scope
- \*.tasmanian.cloud
- API endpoints
- Customer Portal
- Customer-facing infrastructure
Out of Scope
- Social engineering attacks
- Physical attacks on facilities
- Third-party services (Stripe, Cloudflare, etc.)
- Customer applications or data
Security Updates
Subscribe to security advisories:
- RSS: https://tasmanian.cloud/security/rss.xml
- Email: security-alerts@tasmanian.cloud
- Status page: https://status.tasmanian.cloud