Skip to content

Security: ojackson08/aws-serverless-rest-api

Security

SECURITY.md

Security Policy

About This Project

aws-serverless-rest-api is a hardened infrastructure baseline developed by Merkaba AI Risk Management.

Reporting a Vulnerability

If you discover a security vulnerability — including IAM privilege escalation paths or API Gateway bypasses — please report it to:

Email: security@merkabacreatives.org Subject line: [SECURITY] aws-serverless-rest-api — <brief description>

We will acknowledge receipt within 48 hours.

Security Design Notes

  • API Gateway enforces strict request validation.
  • DynamoDB data is encrypted at rest using AWS KMS.

There aren't any published security advisories