Search docs

Docs search

Security Rules

Review implemented validation rules for security-sensitive configuration and governance signals that do not belong to a narrower security category.

Why it matters

Security findings highlight repository evidence that affects access-control, tenant safety, or protected operational behavior.

Overview

Review implemented validation rules for security-sensitive configuration and governance signals that do not belong to a narrower security category.

Security findings highlight repository evidence that affects access-control, tenant safety, or protected operational behavior.

Why it matters

Cloud uses this guidance to help teams interpret local validation findings in organization context without turning the docs into implementation notes.

When this domain drifts, findings become harder to triage, ownership becomes less clear, and architecture review depends too much on individual memory.

Good architectural practices

  • Security-sensitive setup evidence kept visible for reviewers.
  • Findings that complement Authorization and Tenant Isolation checks.
  • Governance context for protected paths that need explicit review.

Common anti-patterns

    Relationship to other architecture areas

    This domain usually overlaps with neighboring validation categories. Use the related pages below to understand the adjacent architecture concerns before changing policy, suppressing a finding, or accepting risk.

    Implemented rules

    These are the currently implemented rules in this category. Use this table for category-level orientation, then open the Rule Catalog when you need rule-specific examples and remediation guidance.

    Rule IDRule titleCategorySeverityShort explanationExample violationRemediation guidanceRule detail
    Security Rules | ArchPilot Docs