SOF-XI Enterprise Security Architecture
Multi-Layered Hardening, RBAC, Two-Factor Authentication & Brute-Force Shields
1. Two-Factor Authentication (2FA) & Passkeys
Enterprise users enforce multi-factor authentication via cryptographically generated TOTP time-based pins, Email OTP verification, and WebAuthn biometrics (FaceID / TouchID / FIDO2 security keys).
2. CPanel Directory & Schema Shielding
Direct browser directory listing is shielded (Options -Indexes). Direct browser access to database stores, environment files (.env, *.sql, *.json), and cPanel configuration trees is strictly blocked at the Apache HTTP level.
3. Double-Entry Immutable Stock & Invoice Ledgers
Inventory counts cannot be modified via arbitrary updates. All inventory adjustments, scrap, transfers, and warehouse issues require immutable, audit-trailed stock movement records.
4. Brute-Force Rate Limiting & Session Inactivity Traps
Login endpoints enforce exponential backoff rate limiting. Active browser sessions expire automatically after 15 minutes of inactivity with instant client-side biometric or credential re-authorization prompts.
5. Database Vault Encryption & Redundant Snapshots
Database stores and tenant records are safeguarded with daily encrypted off-site replication. Cryptographic hashing protects stored user credentials using industry-standard multi-round hashing algorithms.