Update q1-security audit/Ghaymah_Security_Audit.md
هذا الالتزام موجود في:
@@ -1,5 +1,14 @@
|
||||
# Security Audit Report
|
||||
|
||||
|
||||
## 1. Executive Summary
|
||||
|
||||
This report presents an external security assessment of Ghaymah Cloud, a platform-as-a-service (PaaS) provider offering managed compute, container hosting, managed databases, object and block storage, and AI model hosting. The assessment covers fifteen points organized into five categories: Container Security, Network Security, the OWASP Top Ten (subset), Data Security, and Identity and Access Management (IAM).
|
||||
|
||||
The assessment was conducted using publicly available information only. No authenticated access, active scanning, or intrusive testing was performed. Consequently, the findings in this report distinguish between claims made directly by the provider, facts directly observable from the public website, and matters that cannot be confirmed without internal or authenticated access. Two specific findings requiring attention are identified in Section 4.2 and Section 3.3.
|
||||
|
||||
---
|
||||
|
||||
## Ghaymah Cloud (ghaymah.systems)
|
||||
|
||||
| Field | Detail |
|
||||
@@ -12,11 +21,6 @@
|
||||
|
||||
---
|
||||
|
||||
## 1. Executive Summary
|
||||
|
||||
This report presents an external security assessment of Ghaymah Cloud, a platform-as-a-service (PaaS) provider offering managed compute, container hosting, managed databases, object and block storage, and AI model hosting. The assessment covers fifteen points organized into five categories: Container Security, Network Security, the OWASP Top Ten (subset), Data Security, and Identity and Access Management (IAM).
|
||||
|
||||
The assessment was conducted using publicly available information only. No authenticated access, active scanning, or intrusive testing was performed. Consequently, the findings in this report distinguish between claims made directly by the provider, facts directly observable from the public website, and matters that cannot be confirmed without internal or authenticated access. Two specific findings requiring attention are identified in Section 4.2 and Section 3.3.
|
||||
|
||||
## 2. Scope and Methodology
|
||||
|
||||
المرجع في مشكلة جديدة
حظر مستخدم