Skip to content

Security reviewers & program managers · Zero Trust mapping · how we work together

NIST SP 800-207 tenets → POC evidence

#TenetWhat the POC shows
1Secured communicationsAccess / service tokens; edge without public IPs; mTLS where configured
2Least privilegeAllowlisted operators; admin surfaces separated from read paths
3Per-request authorizationSensitive actions re-validated; activity logging on app surfaces
4Dynamic policyLive status and degraded modes if control plane is unreachable
5Data / control plane splitBulk video stays edge-local; MQTT + justified clips to host
6MonitoringProxy health, MQTT telemetry, operator audit trails
7ResilienceOffline / emergency operator paths when primary path fails

Broader AI RMF: NIST AI RMF compliance.

How we engage

Working agreements

  1. One technical channel after kickoff (Slack/Teams shared).
  2. Escalate Access / security issues via Ghost Protocol POC contacts (info@ghostprotocol.us for routing).
  3. Never paste HMAC, device passwords, or private keys into chat—docs hub + private handoff only.
  4. OTA and model pulls are deliberate—written window; see host updates cadence.