Security Posture
Where we stand on the data-layer and edge protections — benchmarked against best-in-class (Cloudflare D1 + the edge security suite). Every line is have / partial / gap, owned by a hat, and editable here. The level-ups we can ship ourselves are tracked; the ones that need you are scoped in Needs a human.
—Coverage
—Have
—Partial
—Gap
—Need a human
Needs a human — let's do these together
Scoped steps that require an account owner or a paid toggle. Everything else, PURE ships itself.
How this board works
A living scorecard, not a one-time audit — so the gaps actually close.
Admin-editable
Add a capability, change a status, reassign an owner, or rewrite the level-up — all from here. Saved to pure_security_posture via gated RPCs (mcp_secpost_upsert), with a local fallback until Code wires the table.
Advance, don't just track
Each card has a one-click Advance (gap partial have) with an audit note. Coverage % moves as work lands.
Human steps are scoped
Anything needing an account owner or a paid toggle (PITR, read replicas, a Turnstile key) surfaces in the top panel with exactly what to do — never buried.
Grounded in real tables
Every "have" cites the live table or function behind it (pure_rate_limits, mfa_factors, audit_log…) so the score is honest, not aspirational.