Infrastructure and dependency management policy
NorthCoast DevOps LLC (ncdLabs) manages cloud infrastructure and software dependencies to keep products operable, patchable, and within intended trust boundaries.
Infrastructure
- Prefer managed cloud platforms (for example Cloudflare Workers, associated storage and queues, and similar providers) with provider-managed physical and hypervisor security.
- Production configuration is treated as code or documented platform configuration; secrets are not committed to repositories.
- Staging and production are separated; production data is not used in casual development copies.
- Administrative cloud access is limited to authorized operators and reviewed when roles change.
- Backups and recovery expectations for critical datastores are defined per product (see product operations docs).
Dependencies
- Application dependencies are pinned via lockfiles (for example npm/pnpm lockfiles, Composer lockfiles, or language equivalents).
- Dependency updates are applied through normal change control; security advisories are prioritized under the vulnerability management policy.
- New third-party services that process customer data require an intentional integration decision (OAuth scopes, data flows, and retention implications).
- Unused services and stale credentials are removed or rotated when features are retired.
Supply chain hygiene
- Prefer official package registries and verified container/base images for production builds.
- CI and deploy tokens are scoped narrowly and rotated on suspected compromise.
- Public repositories must not contain live secrets; scanning and pre-commit hygiene are encouraged on all product repos.
Contact
Infrastructure or dependency security concerns: security@ncdlabs.com.