Automated Interprocedural Compliance Analysis
Data Sovereignty
Audit Report
Target Environment: cyfendo-enterprise/omnichat-backend
Scan Reference ID: SCAN-2026-SOV-88F2A9
Prepared By
Cyfendo SovereignData Core v2.4.0
Date Generated
September 22, 2026
Executive Summary
This report details the automated data sovereignty assessment of the omnichat-backend
environment against the European Sovereign & Defense Standard v2.0. The analysis traces data flow
from source code ingress points through to physical infrastructure sinks to ensure strict regulatory
compliance.
Overall Status: NON-COMPLIANT
The current deployment architecture violates data sovereignty mandates. Sensitive payload data (Chat text, Attachments) and Citizen PII are actively being routed to multi-tenant public hyperscale cloud regions under foreign legal jurisdictions (US East). Immediate architectural remediation is required prior to production release.
1. Assessment Scope & Parameters
Execution Details
| Target Repository | cyfendo-enterprise/omnichat-backend |
| Git Revision | main @ e4b9c1782f91a0c4 |
| Trigger Source | GitHub Actions (PR #142) |
| Execution Latency | 18.4 seconds |
| Hydrated Contexts |
deploy/helm/values-production.yaml terraform/environments/prod/main.tf |
Active Sovereignty Policy
Profile: European Sovereign & Defense Standard v2.0
- Allowed Environments: On-Premise, Self-Hosted Datacenter, Accredited Sovereign Clouds.
- Accredited Regions: aws:eu-sovereign-1, aws:us-gov-west-1.
- Prohibited: Public Hyperscale Clouds (aws:us-*, gcp:us-*, azure:*), Commercial AI APIs, Third-Party Analytics.
- Crypto Exemption: Permitted ONLY if envelope encryption is verified with Customer-Held Keys (HYOK).
2. Data Bill of Materials (D-BOM)
Complete inventory of identified sensitive user data entities, their ingress controllers, and their dynamically resolved physical storage destinations.
| Data Entity / Classification | Ingress Controller | Resolved Destination | Status |
|---|---|---|---|
|
MessagePayload
USER_COMMUNICATION
Chat Text & Attachments
|
POST /api/v1/chat/send (app/routes/chat.py:42) |
s3.us-east-1.amazonaws.com
via S3 Object Store / proxy.internal.lan
|
VIOLATION (SOV-AWS-001) |
|
CitizenProfile
PII / IDENTITY
National ID, Name, DOB
|
POST /api/v1/citizens (app/routes/citizen.py:64) |
prod-db.c7x8y9z.us-east-1.rds.amazonaws.com
via Relational Database
|
VIOLATION (SOV-RDS-002) |
|
UserDocumentArchive
USER_DOCUMENT
|
POST /api/v1/archive (app/routes/archive.py:18) |
minio.storage.corp.internal:9000
On-Premise MinIO Cluster
|
COMPLIANT |
|
AccessAuditRecord
SYSTEM_AUDIT
|
Internal Async Worker (app/workers/audit.py:33) |
s3.eu-sovereign-1.amazonaws.com
AWS EU Sovereign Cloud (HYOK)
|
COMPLIANT |
|
SessionToken
CREDENTIALS
|
POST /api/v1/auth/login (app/routes/auth.py:102) |
redis.auth.svc.cluster.local:6379
In-Cluster K8s Service
|
COMPLIANT |
3. Detailed Violation Findings
SOV-AWS-001: Chat Messages Routed to Public AWS
Source-to-Sink Lineage Trace
Validation Evidence & Proxy Unmasking
- Target Hostname: Appears internal as
http://proxy.internal.lan:8080/storage. - Proxy Resolution: Cyfendo parsed
deploy/k8s/egress-proxy-config.yamlexposing an Nginx reverse proxy routing toomnichat-prod-records.s3.us-east-1.amazonaws.com. - Physical Destination: AWS Public S3 in US East (N. Virginia).
- Cryptographic Check: FAILED. Payload passed as raw UTF-8 JSON without client-side envelope encryption.
Regulatory Impact
Violation of GDPR Chapter V (Art. 44-49). Unlawful international transfer of personal data to a non-adequate third country without standard contractual clauses. Exposes data to US FISA 702 surveillance (Schrems II precedent).
Architectural Advisory Guidance
Zero Data Loss Resolution Strategy:
- Do NOT refactor code to write to local container disk (
open()), which causes data loss in Kubernetes pods. - Update
deploy/helm/values-production.yamlto point directly to the internal MinIO cluster:
storage: endpoint_url: "https://minio.storage.corp.internal:9000" bucket_name: "enterprise-chat-records"
SOV-RDS-002: Citizen PII Written to Foreign AWS RDS
Source-to-Sink Lineage Trace
Validation Evidence & Deployment Hydration
- Code Inspection: Executes generic ORM call
db.session.add(...)relying on environmental configuration. - Hydrated Manifest Binding:
deploy/helm/values-production.yamldefines the database host asprod-citizen-db.c7x8y9z.us-east-1.rds.amazonaws.com. - Physical Destination: AWS RDS multi-tenant infrastructure in us-east-1.
- Policy Violation: Policy SOV-002 strictly mandates physical on-premise containment for citizen national identity data.
Architectural Advisory Guidance
- Re-point production Helm configuration to the on-premise PostgreSQL HA cluster.
- Verify network firewall rules permit pod egress to internal database VLAN 10.240.10.0/24.
database: host: "pg-ha-cluster.db.datacenter.internal" port: 5432
4. Validated Compliant Data Flows
Cyfendo’s multi-tier validation engine automatically confirmed compliance for 26 paths, demonstrating context-aware analysis without raising false positives.
On-Premise MinIO Object Storage
- Invocation:
boto3.client('s3')(AWS SDK utilized). - Audit Resolution: Endpoint overridden to
minio.storage.corp.internal:9000. - Verdict: Validated against Layer 2 (RFC Reserved) and Layer 4 (RFC 1918
Private IP
10.240.15.8). No false alarm raised despite AWS SDK usage.
Zero-Knowledge HYOK Egress
- Target:
s3.eu-sovereign-1.amazonaws.com. - Audit Resolution: Region matches accredited sovereign cloud whitelist.
- Crypto Provenance: Payload verified through approved enterprise wrapper. Key custody traced to on-premise Thales Luna HSM. Cloud provider holds zero key ownership.
5. End-to-End Visual Data Lineage
Architectural flow tracing data from API ingress through application logic to physical infrastructure sinks.
Audit Integrity Attestation
| Formal SARIF 2.1.0 Export | cyfendo-audit-reports/SCAN-2026-SOV-88F2A9.sarif.json |
| Cryptographic Integrity Hash | SHA-256: 7f3a9b2c8e1d4f6a5b8c0e2d4f6a8b0c2e4d6f8a0b2c4d6 |
| Auditor Verification URL | https://app.cyfendo.com/audits/SCAN-2026-SOV-88F2A9 |
| Regulatory Alignment | GDPR Art. 44-49, EU-US DPF, FedRAMP High, NIS2 Directive |
cyfendo rescan SCAN-2026-SOV-88F2A9.