RequirementPreview contractOwning surfacePrimary gateAcceptance evidence
SEC-001SECFixed role templatesCONFIGURATIONsettingsGate 6G03-COV-SEC-001SEC-002SECCustom role builderCONFIGURATIONsettingsGate 6G03-COV-SEC-002SEC-003SECBranch/legal-business scopeCONFIGURATIONsettingsGate 6G03-COV-SEC-003SEC-004SECGranular permissions and approvalsCONFIGURATIONsettingsGate 6G03-COV-SEC-004SEC-005SECPermanent auditCONFIGURATIONsettingsGate 6G03-COV-SEC-005SEC-006SECServer-side tenant/legal-business/branch authorisation decisionCONFIGURATIONsettingsGate 23G03-COV-SEC-006SEC-007SECDatabase-equivalent row isolation and mandatory cross-tenant negative testsCONFIGURATIONsettingsGate 23G03-COV-SEC-007SEC-008SECTLS 1.2 minimum, TLS 1.3 preferred, and encrypted local/service channelsCONFIGURATIONsettingsGate 23G03-COV-SEC-008SEC-009SECDatabase/object/backup/local encryption and sensitive field protectionCONFIGURATIONsettingsGate 23G03-COV-SEC-009SEC-010SECCentral KMS/secret management, rotation, environment separation, and auditCONFIGURATIONsettingsGate 23G03-COV-SEC-010SEC-011SECMinimal encrypted device-bound offline POS cacheCONFIGURATIONsettingsGate 23G03-COV-SEC-011SEC-012SECSigned, certificate-bound, allowlisted Device Bridge and Branch HubCONFIGURATIONsettingsGate 23G03-COV-SEC-012SEC-013SECSeparate append-only tamper-evident business and security logsCONFIGURATIONsettingsGate 23G03-COV-SEC-013SEC-014SECMandatory secret/PII/financial log redactionCONFIGURATIONsettingsGate 23G03-COV-SEC-014SEC-015SECSecurity monitoring, anomaly detection, alert routing, and closure auditCONFIGURATIONsettingsGate 23G03-COV-SEC-015SEC-016SECMalware-scanned, quarantined, tenant-scoped private file handlingCONFIGURATIONsettingsGate 23G03-COV-SEC-016SEC-017SECMFA/re-authenticated, encrypted, expiring, audited data exportCONFIGURATIONsettingsGate 23G03-COV-SEC-017SEC-018SECASVS 5.0.0 Level 2 minimum and selected Level 3 release baselineCONFIGURATIONsettingsGate 23G03-COV-SEC-018SEC-019SECSAST/SCA/secret/IaC/container/DAST/API scans, SBOM, signed artifacts, and rollback gateCONFIGURATIONsettingsGate 23G03-COV-SEC-019SEC-020SECVulnerability remediation SLA and recurring penetration testsCONFIGURATIONsettingsGate 23G03-COV-SEC-020SEC-021SECComprehensive authentication/isolation/offline/file/log/restore security acceptance testsCONFIGURATIONsettingsGate 23G03-COV-SEC-021SEC-022SECSecurity controls are plan-independent integrity requirementsCONFIGURATIONsettingsGate 23G03-COV-SEC-022