Skip to main content
Cyfendo | Sovereignty Audit Report
← Back to Docs Executive Briefing White Paper
Cyfendo Logo
Strictly Confidential

Automated Interprocedural Compliance Analysis

Data Sovereignty
Audit Report

Target Environment: cyfendo-enterprise/omnichat-backend

Scan Reference ID: SCAN-2026-SOV-88F2A9

Prepared By

Cyfendo SovereignData Core v2.4.0

Date Generated

September 22, 2026

Sovereignty Audit Report
SCAN-2026-SOV-88F2A9

Executive Summary

This report details the automated data sovereignty assessment of the omnichat-backend environment against the European Sovereign & Defense Standard v2.0. The analysis traces data flow from source code ingress points through to physical infrastructure sinks to ensure strict regulatory compliance.

2 Confirmed Violations
28 Paths Traced
100% Code & IaC Coverage
0 False Positives

Overall Status: NON-COMPLIANT

The current deployment architecture violates data sovereignty mandates. Sensitive payload data (Chat text, Attachments) and Citizen PII are actively being routed to multi-tenant public hyperscale cloud regions under foreign legal jurisdictions (US East). Immediate architectural remediation is required prior to production release.

1. Assessment Scope & Parameters

Execution Details

Target Repository cyfendo-enterprise/omnichat-backend
Git Revision main @ e4b9c1782f91a0c4
Trigger Source GitHub Actions (PR #142)
Execution Latency 18.4 seconds
Hydrated Contexts deploy/helm/values-production.yaml
terraform/environments/prod/main.tf

Active Sovereignty Policy

Profile: European Sovereign & Defense Standard v2.0

  • Allowed Environments: On-Premise, Self-Hosted Datacenter, Accredited Sovereign Clouds.
  • Accredited Regions: aws:eu-sovereign-1, aws:us-gov-west-1.
  • Prohibited: Public Hyperscale Clouds (aws:us-*, gcp:us-*, azure:*), Commercial AI APIs, Third-Party Analytics.
  • Crypto Exemption: Permitted ONLY if envelope encryption is verified with Customer-Held Keys (HYOK).

2. Data Bill of Materials (D-BOM)

Complete inventory of identified sensitive user data entities, their ingress controllers, and their dynamically resolved physical storage destinations.

Data Entity / Classification Ingress Controller Resolved Destination Status
MessagePayload
USER_COMMUNICATION
Chat Text & Attachments
POST /api/v1/chat/send
(app/routes/chat.py:42)
s3.us-east-1.amazonaws.com
via S3 Object Store / proxy.internal.lan
VIOLATION (SOV-AWS-001)
CitizenProfile
PII / IDENTITY
National ID, Name, DOB
POST /api/v1/citizens
(app/routes/citizen.py:64)
prod-db.c7x8y9z.us-east-1.rds.amazonaws.com
via Relational Database
VIOLATION (SOV-RDS-002)
UserDocumentArchive
USER_DOCUMENT
POST /api/v1/archive
(app/routes/archive.py:18)
minio.storage.corp.internal:9000
On-Premise MinIO Cluster
COMPLIANT
AccessAuditRecord
SYSTEM_AUDIT
Internal Async Worker
(app/workers/audit.py:33)
s3.eu-sovereign-1.amazonaws.com
AWS EU Sovereign Cloud (HYOK)
COMPLIANT
SessionToken
CREDENTIALS
POST /api/v1/auth/login
(app/routes/auth.py:102)
redis.auth.svc.cluster.local:6379
In-Cluster K8s Service
COMPLIANT

3. Detailed Violation Findings

CRITICAL

SOV-AWS-001: Chat Messages Routed to Public AWS

Rule ID: SOV-001 (User Comms Residency Mandate)
Data Class: USER_COMMUNICATION
Confidence: TIER 1 (Mathematically Proven Interprocedural CPG Flow)

Source-to-Sink Lineage Trace

[Ingress: POST /api/v1/chat/send] └── Line 42 (app/routes/chat.py): Parameter 'payload' received │ ├── Line 55 (app/routes/chat.py): Passed to 'chat_service.persist_message' │ ├── Line 88 (app/services/chat_service.py): Passed to 'storage_client.upload_record' │ └── Line 114 (app/services/storage.py): Invocates 's3_client.put_object'

Validation Evidence & Proxy Unmasking

  • Target Hostname: Appears internal as http://proxy.internal.lan:8080/storage.
  • Proxy Resolution: Cyfendo parsed deploy/k8s/egress-proxy-config.yaml exposing an Nginx reverse proxy routing to omnichat-prod-records.s3.us-east-1.amazonaws.com.
  • Physical Destination: AWS Public S3 in US East (N. Virginia).
  • Cryptographic Check: FAILED. Payload passed as raw UTF-8 JSON without client-side envelope encryption.

Regulatory Impact

Violation of GDPR Chapter V (Art. 44-49). Unlawful international transfer of personal data to a non-adequate third country without standard contractual clauses. Exposes data to US FISA 702 surveillance (Schrems II precedent).

Architectural Advisory Guidance

Zero Data Loss Resolution Strategy:

  1. Do NOT refactor code to write to local container disk (open()), which causes data loss in Kubernetes pods.
  2. Update deploy/helm/values-production.yaml to point directly to the internal MinIO cluster:
storage:
  endpoint_url: "https://minio.storage.corp.internal:9000"
  bucket_name: "enterprise-chat-records"
HIGH

SOV-RDS-002: Citizen PII Written to Foreign AWS RDS

Rule ID: SOV-002 (National Identity Containment)
Data Class: PII (National ID, Full Name, DOB)
Confidence: TIER 1 (Formal CPG + IaC Binding)

Source-to-Sink Lineage Trace

[Ingress: POST /api/v1/citizens] └── Line 64 (app/routes/citizen.py): Parameter 'citizen_data' parsed │ ├── Line 72 (app/routes/citizen.py): Instantiates ORM model 'CitizenProfile' │ └── Line 85 (app/routes/citizen.py): Calls 'db.session.add()' and commit()

Validation Evidence & Deployment Hydration

  • Code Inspection: Executes generic ORM call db.session.add(...) relying on environmental configuration.
  • Hydrated Manifest Binding: deploy/helm/values-production.yaml defines the database host as prod-citizen-db.c7x8y9z.us-east-1.rds.amazonaws.com.
  • Physical Destination: AWS RDS multi-tenant infrastructure in us-east-1.
  • Policy Violation: Policy SOV-002 strictly mandates physical on-premise containment for citizen national identity data.

Architectural Advisory Guidance

  1. Re-point production Helm configuration to the on-premise PostgreSQL HA cluster.
  2. Verify network firewall rules permit pod egress to internal database VLAN 10.240.10.0/24.
database:
  host: "pg-ha-cluster.db.datacenter.internal"
  port: 5432

4. Validated Compliant Data Flows

Cyfendo’s multi-tier validation engine automatically confirmed compliance for 26 paths, demonstrating context-aware analysis without raising false positives.

On-Premise MinIO Object Storage

  • Invocation: boto3.client('s3') (AWS SDK utilized).
  • Audit Resolution: Endpoint overridden to minio.storage.corp.internal:9000.
  • Verdict: Validated against Layer 2 (RFC Reserved) and Layer 4 (RFC 1918 Private IP 10.240.15.8). No false alarm raised despite AWS SDK usage.

Zero-Knowledge HYOK Egress

  • Target: s3.eu-sovereign-1.amazonaws.com.
  • Audit Resolution: Region matches accredited sovereign cloud whitelist.
  • Crypto Provenance: Payload verified through approved enterprise wrapper. Key custody traced to on-premise Thales Luna HSM. Cloud provider holds zero key ownership.

5. End-to-End Visual Data Lineage

Architectural flow tracing data from API ingress through application logic to physical infrastructure sinks.

flowchart TD subgraph Ingress ["1. Ingress Endpoints"] direction TB Route1["POST /api/v1/chat/send"] Route2["POST /api/v1/citizens"] Route3["POST /api/v1/archive"] end subgraph InternalProcessing ["2. Application Processing Logic"] direction TB Controller1["chat_service.persist_message()"] Controller2["db.session.add(CitizenProfile)"] Controller3["archive_service.store_pdf()"] end subgraph Sinks ["3. Infrastructure Egress Destinations"] direction TB Proxy["Proxy (proxy.internal.lan:8080)"] S3_AWS["🚨 AWS S3 (us-east-1)"] RDS_AWS["🚨 AWS RDS (us-east-1)"] MinIO["✅ On-Premise MinIO (10.240.15.8)"] end Route1 --> Controller1 Route2 --> Controller2 Route3 --> Controller3 Controller1 -->|HTTP POST| Proxy Proxy -->|Forwarded egress| S3_AWS Controller2 -->|DATABASE_URL via Helm| RDS_AWS Controller3 -->|endpoint_url override| MinIO classDef violation fill:#fee2e2,stroke:#ef4444,stroke-width:2px,color:#7f1d1d; classDef compliant fill:#dcfce7,stroke:#22c55e,stroke-width:2px,color:#14532d; classDef internal fill:#f1f5f9,stroke:#94a3b8,stroke-width:1px,color:#334155; class S3_AWS,RDS_AWS violation; class MinIO compliant; class Route1,Route2,Route3,Controller1,Controller2,Controller3,Proxy internal;

Audit Integrity Attestation

Formal SARIF 2.1.0 Export cyfendo-audit-reports/SCAN-2026-SOV-88F2A9.sarif.json
Cryptographic Integrity Hash SHA-256: 7f3a9b2c8e1d4f6a5b8c0e2d4f6a8b0c2e4d6f8a0b2c4d6
Auditor Verification URL https://app.cyfendo.com/audits/SCAN-2026-SOV-88F2A9
Regulatory Alignment GDPR Art. 44-49, EU-US DPF, FedRAMP High, NIS2 Directive
This report was automatically synthesized by Cyfendo SovereignData Core. For remediation tracking or re-scan triggers, invoke cyfendo rescan SCAN-2026-SOV-88F2A9.