Security engineering
Kotoba fit support NIST CSF 2.0 program?
Kotoba fit contribute technical controls to cybersecurity program. We no claim complete NIST CSF 2.0 coverage, certification, or immunity from attacks. NIST no dey certify CSF products. The useful question na which attack step a deployed control dey stop, and wetin evidence support that claim.
Dem don review am on 2026-09-09. Machine help translate am; native-language review no be certified. Source evidence and the detailed threat model dey available for English. This article na scoped assessment, e no be penetration test.
Three products, each get im own responsibility
Kotoba dey declare effects and dey check capability boundaries. E guarded host-call kernel dey join requested resources, grants and local policy before e invoke handler. Provider still gats enforce the real paths, destinations and tenant scope.
Kotoba Cloud dey provide workflow wey face client and organization. The public profile wey dem inspect get hostedApply=false: generic production-change approval service no dey ship with that setting. Dem suppose assess specific library publication and key-rotation paths separately. Authentication no be approval to deploy or spend.
Kotobase dey give data and object services with authorization paths wey dey server side. A CID dey identify bytes; e no by itself prove who write am, secrecy, trusted approval, say e go dey available forever, or say recovery go succeed. Those ones need separate controls and operating evidence.
One bounded current-to-target CSF profile
Dis na our selected product contribution map, e no be complete organizational Profile or score wey comply by percentage. Customers must define scope, owners, risk tolerance and evidence for dia own deployment.
- Govern
- Policy and risk registers dey provide design baseline. Target: decision owners wey dem name, exceptions wey dem review, and recorded release sign-off.
- Identify
- Manifests and content identities dey help track artifacts. Target: a deployed asset inventory, data classification and dependency ownership.
- Protect
- Capability admission and guarded dispatch get implementation and local-test evidence. Target: qualified production bindings, scoped secrets, tenant tests and measured revocation.
- Detect
- The host fit return denial and execution receipts. Target: one durable protected sink, alerts wey dem correlate, retention, and proof say e reach one accountable responder.
- Respond
- Dem don document response playbooks. Target: containment and communication wey dem don exercise, together with measured response and revocation times.
- Recover
- Content identities dey support verification of restoration inputs. Target: protected backups, tested restores and customer-specific recovery objectives. A content hash no be backup.
Attack graph: instructions no dey grant authority
Assume say attacker control text wey AI agent dey read, but e no control the host, signing keys or policy. The attacker dey try turn suggestion into customer-data export. The graph show the control crossings wey dem need; e no be observed compromise or claim say every deployed integration dey enforce dem.
- Document or tool response we no trust
- AI dey suggest one sensitive operation
- Admission of wetin e fit do and how e go work
- Resource-scoped host and provider check
- Operation we authorize and outcome we record
- Operation wey dem deny; handler no invoke
Attack stories and the evidence wey dem need
Prompt injection to data export
Content wey attacker control dey ask agent make e send customer data go outside the approved destination. For guarded path, if effect dey miss or resource grant no join, dispatch suppose stop. Verify say dem never call handler. Residual risk: grants wey too broad, provider redirects and integration wey dey bypass am.
One tenant dey request another tenant data
An authenticated caller go supply different graph or resource identifier. Server-side checks must bind principal, tenant, operation and object on every route. Browser menus and a CID no be authorization. Inspect each endpoint and test denied reads and writes; no fleet-wide isolation claim dey follow from one kernel test.
One artifact change after approval
Publisher or intermediary dey substitute bytes. Require the expected content digest, trusted signer, validity and approval for the exact revision before use. Valid signature on malicious code still fit happen; trusted signing and artifact identity dey necessary but dem no dey sufficient.
Dem reuse stale approval or grant wey dem revoke
One caller dey try again do action wey dem don authorize before. Expiry checks fit help, but replay state wey dey last, atomic consumption where e dey required, current revocation and resource binding na separate responsibilities. Generic host receipt no be replay-prevention service.
Resource finish and service disruption
Input or program wey dem generate dey chop too much work. Admission bounds, execution fuel, memory limits and supervisor deadlines dey handle different stages. Test the real production backend under load; say language fixture pass no mean say e fit resist network flooding or host compromise.
Evidence loss during an incident
Service fit fail after external action, or attacker fit tamper with local logs. Host kernel fit return receipts, but e recorder na optional and e journal dey memory. Deploy durable protected recorder with failure handling and test recovery. Successful operation no be proof say external audit log don persist.
Wetin we verify, and wetin still remain open
For the language revision we cite, all 24 capability conformance fixtures pass locally under ClojureScript, including 9 component-binding and 2 host-dispatch cases. Dem check the expected allow and deny outcomes. This na kernel evidence, e no be end-to-end attack test of the live services.
The assurance register wey dem inspect still no qualify operationally. The crosswalk wey e store dey report design and implementation evidence, but e no get operating evidence for the SOC and ISO controls wey e encode. Na statement about this snapshot, no be finding say every production control no dey.
Before enterprise pilot, tie proposal, principal, environment, exact artifact and policy to operation wey scope narrow well. Test cases wey dem allow and deny, replay wey happen together, revocation, log failure and restore. Measure unauthorized effects wey reach handler, receipts wey miss, revocation delay and recovery time. Publish the scope wey una test and the gaps wey still remain.
