Skip to content

@platphorm_dictionary

Public approved definitions attributed to this handle. Private author metadata is not exposed.

Access Phishing Resistance is a security identity control that reduces success of credential theft attacks for authorization and privilege control. It uses passkeys, hardware-backed factors, and origin checks so teams can protect sign-in flows while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Access Phishing Resistance when a role gained new permissions, so the team could protect sign-in flows before the risk review began.

Load Balancer Traffic Shaper is a networking control mechanism that limits or prioritizes flows across links for traffic distribution. It uses queues, rate limits, and quality-of-service rules so teams can protect important traffic while keeping evidence, reliability, and public-safe operational boundaries clear.

The network engineering team used Load Balancer Traffic Shaper when traffic shifted between regions, so the team could protect important traffic before traffic crossed a service boundary.

Latency Anycast Endpoint is a networking routing pattern that advertises one address from multiple locations for time between request and response. It uses regional announcements, health checks, and traffic steering so teams can serve users from nearby healthy sites while keeping evidence, reliability, and public-safe operational boundaries clear.

The network engineering team used Latency Anycast Endpoint when a user saw slow responses, so the team could serve users from nearby healthy sites before traffic crossed a service boundary.

CDN Egress Policy is a networking outbound control that decides where workloads may send traffic for content delivery and edge caching. It uses allowlists, identity, and logging so teams can reduce exfiltration and SSRF risk while keeping evidence, reliability, and public-safe operational boundaries clear.

The network engineering team used CDN Egress Policy when a cache region served an asset, so the team could reduce exfiltration and SSRF risk before traffic crossed a service boundary.

Subnet Egress Policy is a networking outbound control that decides where workloads may send traffic for address segmentation. It uses allowlists, identity, and logging so teams can reduce exfiltration and SSRF risk while keeping evidence, reliability, and public-safe operational boundaries clear.

The network engineering team used Subnet Egress Policy when a workload moved networks, so the team could reduce exfiltration and SSRF risk before traffic crossed a service boundary.

CDN Health Probe is a networking availability check that tests whether a service or path can receive traffic for content delivery and edge caching. It uses timed requests, thresholds, and regional checks so teams can send traffic only to healthy targets while keeping evidence, reliability, and public-safe operational boundaries clear.

The network engineering team used CDN Health Probe when a cache region served an asset, so the team could send traffic only to healthy targets before traffic crossed a service boundary.

Incident Response Trust Boundary is a security security boundary that defines where assumptions, identities, or permissions change for security event handling. It uses network edges, service roles, and data classifications so teams can avoid accidental privilege crossing while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Incident Response Trust Boundary when an alert escalated to response, so the team could avoid accidental privilege crossing before the risk review began.

CDN Rate Limit is a networking traffic control that caps request volume over a period for content delivery and edge caching. It uses identity keys, windows, and response policies so teams can protect services from overload while keeping evidence, reliability, and public-safe operational boundaries clear.

The network engineering team used CDN Rate Limit when a cache region served an asset, so the team could protect services from overload before traffic crossed a service boundary.

VPN Traffic Shaper is a networking control mechanism that limits or prioritizes flows across links for private tunnel connectivity. It uses queues, rate limits, and quality-of-service rules so teams can protect important traffic while keeping evidence, reliability, and public-safe operational boundaries clear.

The network engineering team used VPN Traffic Shaper when a remote user connected, so the team could protect important traffic before traffic crossed a service boundary.

Secrets Patch Window is a security remediation schedule that sets when a fix should be applied for keys, tokens, and credentials. It uses risk severity, testing needs, and maintenance constraints so teams can repair systems without unnecessary disruption while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Secrets Patch Window when a secret appeared in logs, so the team could repair systems without unnecessary disruption before the risk review began.

Secrets Phishing Resistance is a security identity control that reduces success of credential theft attacks for keys, tokens, and credentials. It uses passkeys, hardware-backed factors, and origin checks so teams can protect sign-in flows while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Secrets Phishing Resistance when a secret appeared in logs, so the team could protect sign-in flows before the risk review began.

Secrets Policy Decision is a security authorization decision that determines whether an action should be allowed for keys, tokens, and credentials. It uses identity, resource, context, and policy evaluation so teams can enforce least privilege while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Secrets Policy Decision when a secret appeared in logs, so the team could enforce least privilege before the risk review began.

Secrets Secret Scanner is a security preventive control that finds credentials before they spread for keys, tokens, and credentials. It uses pattern matching, entropy checks, and allowlists so teams can stop accidental key exposure while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Secrets Secret Scanner when a secret appeared in logs, so the team could stop accidental key exposure before the risk review began.

Incident Response Forensic Snapshot is a security investigation artifact that captures system state for later review for security event handling. It uses logs, configuration, hashes, and time-bounded data so teams can analyze incidents without changing evidence while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Incident Response Forensic Snapshot when an alert escalated to response, so the team could analyze incidents without changing evidence before the risk review began.

Incident Response Patch Window is a security remediation schedule that sets when a fix should be applied for security event handling. It uses risk severity, testing needs, and maintenance constraints so teams can repair systems without unnecessary disruption while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Incident Response Patch Window when an alert escalated to response, so the team could repair systems without unnecessary disruption before the risk review began.

Service Mesh Ingress Rule is a networking boundary rule that controls how external traffic enters a service for east-west service communication. It uses hostnames, paths, protocols, and policy checks so teams can keep entry points predictable while keeping evidence, reliability, and public-safe operational boundaries clear.

The network engineering team used Service Mesh Ingress Rule when a service called another service, so the team could keep entry points predictable before traffic crossed a service boundary.

Incident Response Phishing Resistance is a security identity control that reduces success of credential theft attacks for security event handling. It uses passkeys, hardware-backed factors, and origin checks so teams can protect sign-in flows while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Incident Response Phishing Resistance when an alert escalated to response, so the team could protect sign-in flows before the risk review began.

Incident Response Policy Decision is a security authorization decision that determines whether an action should be allowed for security event handling. It uses identity, resource, context, and policy evaluation so teams can enforce least privilege while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Incident Response Policy Decision when an alert escalated to response, so the team could enforce least privilege before the risk review began.

Incident Response Secret Scanner is a security preventive control that finds credentials before they spread for security event handling. It uses pattern matching, entropy checks, and allowlists so teams can stop accidental key exposure while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Incident Response Secret Scanner when an alert escalated to response, so the team could stop accidental key exposure before the risk review began.

Endpoint Detection Rule is a security security analytic that matches suspicious behavior or known indicators for user device and server protection. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Endpoint Detection Rule when a workstation reported suspicious activity, so the team could surface actionable alerts before the risk review began.