Security Threat Model
This document outlines MetaPilot's formal threat model, detailing trust boundaries, attack vectors, potential threat scenarios, and implemented security controls.
1. Trust Boundaries & Attack Surfaces
Rendering diagram...
️ 2. Threat Scenarios & Mitigations Matrix
| Threat Category | Potential Risk / Vector | Impact Level | Implemented Mitigation Control |
|---|---|---|---|
| Cross-Tenant Data Leakage | Tenant A attempts to read/modify Tenant B's contacts or messages via API manipulation | Critical | |
| Meta Access Token Exposure | Attacker dumps database or logs and steals Meta WhatsApp access tokens | Critical | Credentials stored using Fernet AES-256 encryption; |
| Spoofed Meta Webhook Inject | Attacker sends fake incoming messages to | High | Mandatory |
| JWT Token Hijacking | Access token intercepted or stolen from client memory | High | Short access token TTL (15 mins); HTTPS enforced; refresh token rotation & blacklist on logout ( |
| Broadcast Abuse / Spam | Compromised user schedules millions of messages triggering Meta ban | High | Token Bucket Rate Limiting (default 50 msgs/sec per tenant); Super Admin quota enforcement. |
| Brute-Force Authentication | Attacker attempts password spraying on | Medium | Rate limiting middleware; strong password validator rules (min 8 chars, complexity checks). |
3. Key Rotation & Emergency Response
- Fernet Encryption Key Rotation: Executed via operational runbook rotate-fernet-keys.md.
- Security Incident Escalation: Follow policies outlined in SECURITY.md.