Skip to main content

158 posts tagged with "Compliance"

Regulatory compliance and legal frameworks

View all tags

CIS Shipped the First MCP Server Benchmark: A 10-Domain Hardening Checklist Before Agents Get Production Credentials
·Dora Noda·11 min

CIS Shipped the First MCP Server Benchmark: A 10-Domain Hardening Checklist Before Agents Get Production Credentials

The CIS MCP Server Benchmark v1.0.0 packs 55 recommendations into 10 security domains — here is each domain mapped to a concrete pass/fail check for a self-hosted PaaS deploy/operate surface, plus the four gaps to close before agent credentials touch production.

Model Context Protocol
AI agents
cybersecurity
self-hosting
+1
CIS Published the First MCP Server Hardening Baseline — Here's What It Demands of Deploy-From-Chat Tools
·Dora Noda·10 min

CIS Published the First MCP Server Hardening Baseline — Here's What It Demands of Deploy-From-Chat Tools

CIS released the first consensus hardening baseline for MCP servers on September 16, 2026: 55 recommendations across 10 domains. Here is how each domain maps onto MCP tools that deploy, roll back, and read secrets — what a sane self-hosted surface already passes, and what still needs building.

Model Context Protocol
AI agents
security
self-hosting
+1
Compliance Is the Moat: What Render's SOC 2, ISO 27001, and HIPAA Posture Really Costs to Rebuild on Hardware You Own
·Dora Noda·9 min

Compliance Is the Moat: What Render's SOC 2, ISO 27001, and HIPAA Posture Really Costs to Rebuild on Hardware You Own

Render's SOC 2, ISO 27001, and HIPAA posture is the hardest part of Render to replace. A line-by-line accounting puts the first-year rebuild at $40,000–$85,000 — plus the one gap, the HIPAA BAA, that is a veto rather than a cost.

compliance
self-hosting
PaaS
migration
+1
GitLab's CVSS 10.0 File-Read Flaw: The Self-Hosted Patch Playbook for a 24-Hour Probe Window
·Dora Noda·9 min

GitLab's CVSS 10.0 File-Read Flaw: The Self-Hosted Patch Playbook for a 24-Hour Probe Window

CVE-2026-85706 lets unauthenticated attackers read any file off a self-managed GitLab server — and honeypots saw probes within 24 hours of disclosure. The four-step playbook: inventory, patch, forensic triage, and secret rotation.

security
self-hosting
cybersecurity
compliance
Tenant Offboarding Is a Data-Deletion Problem: The GDPR Erasure Checklist Across Volumes, Snapshots, Logs, Registries, and Backups
·Dora Noda·13 min

Tenant Offboarding Is a Data-Deletion Problem: The GDPR Erasure Checklist Across Volumes, Snapshots, Logs, Registries, and Backups

Deleting a churned tenant's namespace takes ninety seconds. Erasing their personal data from volumes, snapshots, logs, registries, backups, DNS, and metrics takes a checklist — here it is, with each store's deletion mechanism, retention clock, and an honest accounting of what cannot be deleted.

privacy
compliance
Kubernetes
self-hosting
+1
The EU CRA's 24-Hour Clock Is Now Running: What the First Week of Mandatory Vulnerability Reporting Demands of a Self-Hosted PaaS Vendor
·Dora Noda·11 min

The EU CRA's 24-Hour Clock Is Now Running: What the First Week of Mandatory Vulnerability Reporting Demands of a Self-Hosted PaaS Vendor

Since September 11, 2026, software vendors selling into the EU must report actively exploited vulnerabilities within 24 hours through ENISA's Single Reporting Platform. Here is the three-stage clock, what the first week of coverage revealed, and the readiness checklist for a self-hosted PaaS vendor.

cybersecurity
compliance
regulation
self-hosting
Your Kubernetes Cluster Already Negotiates Post-Quantum TLS. Your Edge Probably Doesn't
·Dora Noda·12 min

Your Kubernetes Cluster Already Negotiates Post-Quantum TLS. Your Edge Probably Doesn't

Kubernetes v1.33 already negotiates hybrid post-quantum TLS on the control plane — but your ingress, tenant certificates, and secrets layer each need their own verdict. A layer-by-layer readiness inventory with the CNSA 2.0 deadlines that set the pace.

Kubernetes
cryptography
security
self-hosting
+1
Buildpacks RFC 0130: Zero-Config OCI Provenance Your SOC 2 Auditor Can Actually Read
·Dora Noda·11 min

Buildpacks RFC 0130: Zero-Config OCI Provenance Your SOC 2 Auditor Can Actually Read

Cloud Native Buildpacks approved RFC 0130, stamping buildpack images with source, commit, and version metadata automatically. What that buys a SOC 2 or FedRAMP audit, what unsigned annotations can't prove, and the SBOM plus signed-attestation checklist that closes the gap.

PaaS
compliance
security
self-hosting
DMCA Takedowns Land on the Platform, Not the Tenant: The Notice-and-Takedown Runbook a Self-Hosted PaaS Needs Before the First Complaint
·Dora Noda·12 min

DMCA Takedowns Land on the Platform, Not the Tenant: The Notice-and-Takedown Runbook a Self-Hosted PaaS Needs Before the First Complaint

The moment tenants serve content from your domains, abuse notices land on your desk — and safe-harbor protection depends on machinery built before the first one. A concrete DMCA and DSA runbook for self-hosted PaaS operators: designated agent, repeat-infringer policy, per-tenant suspension, and shared-domain defense.

self-hosting
PaaS
compliance
security
+1
Showing 1–9 of 158 posts