Skip to main content

Binary Networks — Status & Index

A single map of every doc, grouped by what it is: something we're building, something already deployed, or a governing policy. Files stay where they live; this page is the cross-cutting view.

Status legend: 🟢 Deployed / As-built · 🟡 In progress · ⚪ Planned (spec) · 📘 Approved policy


1. Build Plan — the S.E.T product (being built)

The S.E.T (Secure·Enforce·Train) GRC platform. These are specifications for the product we are building across Phases 0–7. Most are ⚪ specs until their phase lands. The application code lives in IONTWRKS/set-app (monorepo); infra/governance in IONTWRKS/set-platform.

DocCoversStatus
OverviewProduct vision, tenants, scope
UI / UXNeumorphism design system
Tech StackReact/Vite · NestJS · Postgres · WorkOS
ArchitectureSystem architecture
AuthenticationWorkOS (AuthKit / SSO / MFA)
Multi-tenancyTenant = WorkOS org ⇄ Postgres schema
ObservabilityLogging tiers, audit events
Data ModelSchema-per-tenant, entities
Environmentsdev / nonprod / prod
Admin User FlowsBack-office journeys
Customer User FlowsCustomer-portal journeys
DownloadsExports / file handling
Report GenerationPDF / compliance reports
NotificationsEmail + scheduled jobs (BullMQ)
Testing & QATest strategy, isolation tests
SearchSearch architecture

Roadmap: Phase 0 (scaffold → local Postgres/Redis → Drizzle + tenant provisioning → WorkOS) → Phase 1 (identity/tenancy) → Phases 2–7. The Phase/Module/Scope breakdown (with QA + design hours) is tracked in the external SET - Phases Modules Scopes workbook.


2. Completed / As-built — what's deployed today

Platform security & evidence (delivered this cycle)

CapabilityWhere it's documentedStatus
CI security gate — one reusable security-core.yml (TruffleHog · OSV · Trivy · Semgrep · zizmor/actionlint/pin-ratchet) called by every repoSupply Chain § As-built implementation🟢
Evidence Archive (WORM S3)iontwrks-ci-evidence, eu-north-1, acct 429134227608, gha-log-archive OIDC role, log-archive.yml pipelineEvidence & Retention §8🟢
Org guardrails — 2FA required, default-no-access; per-repo branch protection; org rollout across 6 reposSupply Chain § As-built🟢
Repo topologyset-platform (infra/cage) vs set-app (product)repos + set-app/CLAUDE.md🟢
code-graph cross-repo brain — Terraform module (merged, deploy pending)set-platform/infra/code-graph🟡

Scanners — live product

The scanners platform runs on ECS Fargate (eu-north-1). Its docs are as-built. 🟢

GolemSec — deployed lab environment 🟢

Overview · AWS Architecture · Build Status · DR (and 7 more under golemsec/)


3. SDLC & Policies — governance 📘

The umbrella lifecycle policy and its version-controlled sub-policies (ISO 27001 / SOC 2 / NIST SSDF aligned). All 📘 Approved.

Policies (governance/policies/): Access Reviews · Audit Testing Scope · Backup & Recovery · Change Management · Cryptography Standard · DAST & Pen-testing · Decommissioning · Developer Security Training · Evidence & Retention · Incident Response · Release Gate Criteria · Risk Assessment · Roles & Responsibilities · Root-Cause Analysis · Secure Coding Standard · Security Requirements & Threat Modeling · Separation of Duties · Test Data Protection · Vulnerability Management


How to keep this current: when a Build-Plan spec becomes deployed, move its row to §2 and flip its badge to 🟢. When a new control ships, add it to §2 and register its evidence in Evidence & Retention §3.