GHOSTSOFTWARE by Logic Foundry
Architecture proposal

Security & tenancy boundaries

Make the trust boundary explicit in every integration.

Authenticate first

Use the provider’s supported authentication mechanism over TLS. Keep credentials server-side and scoped to the integration’s required actions. Verify signatures only where the sender actually supports them; do not describe a custom signature header as a vendor feature.

Authorize separately

A valid transport credential proves the integration identity, not ownership of every device. Bind it to an expected application, then authorize the device against your registry. Every query and background job must retain its tenant context.

Minimize what is exposed

  • Keep device root keys out of web clients, examples and logs.
  • Limit request body size, parse time and per-integration throughput.
  • Reject unknown schema versions and unsupported event types.
  • Rotate credentials through a controlled overlap and revocation process.
  • Record administrative changes without storing secret values.

Threat review

Review replay, duplicate effects, cross-tenant routing, malicious payloads, compromised devices and unavailable providers. Test each boundary rather than assuming a framework provides it. Ghost Signal supplies validation, not a complete security system or a compliance certification.