Feature Store  ·  View 19 of 21  ·  Assurance

Security Trust Zones

Five zones, and one rule enforced at registration rather than at read.

Editable source SVG draw.io All views
Corporate network Data scientist Corporate IdP OIDC Perimeter Catalogue ALB WAF + OIDC Registry API token-scoped No public serving endpoint VPC only, by design Application — private VPC Serving API mTLS, IRSA On-demand runtime sandboxed, 2 ms Compiler Training-set service Data — private endpoints Online store KMS CMK Offline store Lake Formation grants Registry Audit log Object Lock Restricted PII-derived groups purpose-limited Serving log inherits max class HTTPS + id token scoped session group ACL check scoped read grant class escalation blocked sampled Feature Store — Security Trust Zones Person or role External / third party Interface / broker Risk / gap Application we own Data store synchronous batch failure / alternate event / async A feature cannot be derived from a restricted column into a group of lower classification. That rule is enforced at registration, not at read. v 1.0 · owner Data Platform Architecture · date 2026-09

Decisions

  • A feature cannot be derived from a restricted source column into a group of lower classification. Enforced at registration, because enforcing it at read means the data has already been copied.
  • The serving log inherits the classification of the most restricted group it contains, which stops the evidence trail becoming an unclassified copy of restricted data.
  • There is no public serving endpoint. That is a listed control, not an omission.

Assumptions

  • Customer-managed KMS keys for restricted groups; Lake Formation column and row grants on the offline store; audit retained 7 years under Object Lock.
  • Entity erasure within 24 h online and 30 days offline, reflected in future point-in-time joins.

Risks

  • Purpose limitation is granted at the group, not checked at the read, until phase 3. Between now and then an authorised consumer can use a feature for a purpose it was not granted for.
  • Offline erasure at 30 days means a point-in-time join run on day 29 can still return an erased entity's values.