Minimize trust and exposure
Keep databases and operational services away from direct public access, encrypt sensitive resources, limit credentials, and require authenticated, authorized pathways into tenant data.
Trust Through Architecture and Operations
OriginSpan provides connected product infrastructure for organizations that need durable identity, controlled access, tenant isolated data, dependable event history, and resilient operating foundations.
Security controls, hosting, recovery objectives, independent assurance, and service commitments are documented for each customer engagement and reflected in the applicable agreement.
Our Operating Posture
OriginSpan combines managed cloud services, least-privilege access, tenant-aware authorization, encrypted data paths, controlled deployment workflows, monitoring, and recovery planning. The objective is to reduce avoidable risk while preserving the ability to operate and scale.
Keep databases and operational services away from direct public access, encrypt sensitive resources, limit credentials, and require authenticated, authorized pathways into tenant data.
Use structured logs, metrics, alarms, endpoint health checks, budget controls, and failure queues so that abnormal conditions can be identified and investigated.
Retain backups, protect critical resources from accidental deletion, isolate failed asynchronous work, and maintain controlled recovery and deployment paths.
Security by Design
No single technology is treated as the security boundary. Identity, application authorization, tenant membership, permissions, database enforcement, network isolation, and auditability reinforce one another.
OriginSpan uses managed identity services, short-lived signed tokens, authorization code flow with PKCE, and verified WebAuthn passkeys as the preferred native method. Password plus software-token TOTP remains the controlled fallback. OriginSpan does not receive biometric data, device PINs, passkey private keys, or authenticator secrets.
Shared company stations can require a fresh managed sign in, block local passkey enrollment, support phone passkeys or assigned security keys, synchronize policy across tabs, provide user switching, and apply idle locking and shift limits.
Federated sign in and additional authentication options can be configured according to the customer’s identity provider, recovery policies, migration needs, and deployment requirements.
The selected organization, role, and permission are validated at the API boundary. PostgreSQL row-level security provides an additional database enforcement layer so a request cannot rely on client-side filtering to protect another customer’s data.
Platform data, logs, queues, object storage, and credentials use encrypted AWS services and customer-managed key boundaries where appropriate. Application database connections travel through a TLS-required RDS Proxy, and database credentials are stored in AWS Secrets Manager rather than application source code.
Application workloads run within private subnets and reach PostgreSQL through a narrowly permitted network path. Private AWS endpoints reduce unnecessary public service traffic, and storage origins are not exposed as public website buckets.
Infrastructure and application changes are defined as code, tested, reviewed, and deployed through protected GitHub environments using AWS OIDC. Routine deployments do not depend on a developer storing long-lived AWS access keys or personal access tokens in automation.
Scanner workflows are designed to normalize identifiers without routinely storing raw scan payloads. Camera frames and selected images are decoded locally in the browser and are not uploaded merely to resolve a barcode. Sensitive error responses are sanitized rather than echoing cross-tenant or raw identifier details.
Protection Across Critical Workflows
OriginSpan applies these controls across products, operational lifecycle, evidence, exports, and Digital Product Passport delivery.
Product activation, custody transfer, lifecycle correction, and customer export can require fresh authentication followed by a deliberate review and resubmission.
Accepted operational commands update the current snapshot and append immutable lifecycle, authorization-audit, and transactional-outbox records in one tenant-scoped transaction. Corrections preserve the original event and add a visible supersession chain.
Evidence uses private, KMS-encrypted, versioned storage, exact key and checksum policies, quarantine, malware-result reconciliation, and exact-version download authorization. The application has no evidence delete authority.
Public resolver documents are generated only from a privacy-minimized public projection. Restricted passport values require managed authentication and tenant authorization and are not embedded in the public resolver record.
Protected Request Path
The browser is not trusted to decide what a user may see. Protected actions move through managed identity, API authorization, application permission checks, private network controls, and database-enforced tenant isolation.
Signed tokens establish the user identity after the configured authentication factors succeed.
Required token audience, scope, selected tenant, active membership, role, and permission are evaluated.
Serverless application code runs within controlled network boundaries rather than exposing the database publicly.
Forced row-level security constrains data operations to the authorized tenant context.
Operational signals support detection, troubleshooting, and review without intentionally logging sensitive raw scan data.
Scalability
OriginSpan separates edge delivery, API execution, relational data, resolver indexes, object storage, and asynchronous processing so that each layer can scale according to its own workload rather than forcing the entire system onto one server.
Static application assets are delivered through Amazon CloudFront from private, versioned object storage. This reduces origin load and places frequently requested content closer to users.
API Gateway and AWS Lambda allow application capacity to respond to request volume without maintaining a permanently sized application-server fleet. Throttling and concurrency controls protect downstream dependencies from uncontrolled bursts.
Aurora PostgreSQL Serverless v2 can adjust database capacity within configured limits. RDS Proxy pools and governs application connections so serverless execution does not create an unbounded number of direct PostgreSQL sessions.
DynamoDB provides a separately scalable projection for high-volume identity and resolver access patterns, allowing product lookup traffic to grow without requiring every public resolution to execute a complex relational query.
EventBridge, encrypted queues, and dead-letter queues separate accepted business events from downstream work. Slow or failed consumers can be isolated and retried without blocking the original request path.
Scaling is not treated as unlimited. Database ranges, API throttles, concurrency, budgets, storage policies, and customer usage allowances provide measurable control over cost, reliability, and noisy-neighbor risk.
Resilience and Recoverability
Resilience is built through availability-zone separation, managed-service recovery, protected data, health monitoring, failure isolation, and controlled operational procedures—not by assuming that every dependency will always be available.
OriginSpan uses separated network and database placement so core dependencies are not intentionally concentrated in one physical location.
Managed backups, point in time recovery, retention, and deletion protection help preserve critical data and infrastructure.
Encrypted outbox and dead-letter queues preserve failed asynchronous work for investigation and controlled retry instead of repeatedly blocking a customer-facing request or silently discarding the event.
CloudWatch logs, metrics, dashboards, alarms, enhanced database monitoring, external endpoint health checks, DNS operational alarms, and SNS notifications provide an observable foundation for incident response.
Account-qualified infrastructure, exact operator confirmations, protected GitHub environments, restricted OIDC roles, and narrowly scoped deployment workflows reduce the risk of changing the wrong account, environment, DNS zone, or application stack.
Public endpoints and authoritative DNS conditions are monitored. DNSSEC is introduced through a staged process that separates hosted-zone signing from the public registrar chain-of-trust change, preserving an explicit approval and rollback boundary.
Recovery objectives, ownership, alert routing, restore procedures, dependency limits, and incident runbooks are defined for the applicable service scope.
Assurance and Transparency
OriginSpan separates platform controls, customer requirements, contractual commitments, and independent assurance so each engagement has a clear and reviewable security scope.
Certifications, standards claims, and service commitments are communicated when they apply to the service scope and are supported by the appropriate review or evidence.
Security Questions
OriginSpan is built on Amazon Web Services. Hosting region, residency, and contractual requirements are defined for the applicable service offering and customer agreement.
Managed identity, permissions, tenant membership, database row level controls, encryption, private networking, and audit history reinforce one another beyond the user interface.
Evidence can use private encrypted versioned storage, integrity checks, malware processing, and controlled access tied to the authorized tenant and lifecycle record.
Applicable assurance, security requirements, recovery objectives, service levels, and support commitments are documented in customer review materials and the governing agreement.
Security Requirements Are Part of the Scope
A focused OriginSpan engagement can document the data classification, identity model, integration boundaries, retention requirements, expected volumes, recovery objectives, and assurance roadmap needed for a confident deployment decision.