NP-200 system security design review
NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007
PRJ-2026-0042-DRV-0001Threat review
Treatment planner
Remediation options per threat; adoption creates a design control and a verification obligation.
Option states
| Segment | Count | Share |
|---|---|---|
| Adopted | 8 | 62% |
| Evaluating | 3 | 23% |
| Deferred | 1 | 8% |
| Rejected | 1 | 8% |
High/Critical threats with an adopted option
Adopted options with control + obligation
REM-201Mutual device/service authentication on the remote command pathAdopted
- Proposed (passed)
- Evaluating (passed)
- Adopted (current)
- Implementing (pending)
- Implemented (pending)
- Verified (pending)
TradeoffsCoverageDesign actionResidual effectCatalogObjectiveIdentity and access
ADOPTTomas Novak21 Apr 2026
REM-202Signed nonce-bound commands with anti-replay windowAdopted
- Proposed (passed)
- Evaluating (passed)
- Adopted (current)
- Implementing (pending)
- Implemented (pending)
- Verified (pending)
TradeoffsCoverageDesign actionResidual effectCatalogObjectiveData and command integrity
ADOPTTomas Novak21 Apr 2026
REM-203Gateway network allowlist for command listenerdefense-in-depthAdopted
- Proposed (passed)
- Evaluating (passed)
- Adopted (current)
- Implementing (pending)
- Implemented (pending)
- Verified (pending)
TradeoffsCoverageDesign actionResidual effectCatalogObjectiveArchitecture change
ADOPTTomas Novak21 Apr 2026
Owner: Owen Blake (Gateway platform)Target: Gateway 2.5 (Q2 2026)Due: 29 May 2026DC-000316VOB-000213
REM-105Authenticated maintenance access and service-port lockdownVerified
- Proposed (passed)
- Evaluating (passed)
- Adopted (passed)
- Implementing (passed)
- Implemented (passed)
- Verified (current)
TradeoffsCoverageDesign actionResidual effectCatalogObjectiveIdentity and access
ADOPTTomas Novak26 Jan 2026
Owner: Noor Haddad (Firmware platform)Target: FW 3.1.4 (shipped Feb 2026)Due: 13 Feb 2026DC-000209VOB-000108
REM-210End-to-end signed firmware with boot-time verificationEvaluating
- Proposed (passed)
- Evaluating (current)
- Adopted (pending)
- Implementing (pending)
- Implemented (pending)
- Verified (pending)
TradeoffsCoverageDesign actionResidual effectCatalogObjectiveUpdate patchability
No decision recorded
Owner: Noor Haddad (Firmware platform)
REM-211Anti-rollback version policy on update agentEvaluating
- Proposed (passed)
- Evaluating (current)
- Adopted (pending)
- Implementing (pending)
- Implemented (pending)
- Verified (pending)
TradeoffsCoverageDesign actionResidual effectCatalogObjectiveUpdate patchability
No decision recorded
Owner: Noor Haddad (Firmware platform)
REM-202Signed nonce-bound commands with anti-replay windowAdopted
- Proposed (passed)
- Evaluating (passed)
- Adopted (current)
- Implementing (pending)
- Implemented (pending)
- Verified (pending)
TradeoffsCoverageDesign actionResidual effectCatalogObjectiveData and command integrity
ADOPTTomas Novak21 Apr 2026
REM-212BLE secure pairing with app-layer session bindingEvaluating
- Proposed (passed)
- Evaluating (current)
- Adopted (pending)
- Implementing (pending)
- Implemented (pending)
- Verified (pending)
TradeoffsCoverageDesign actionResidual effectCatalogObjectiveIdentity and access
No decision recorded
Owner: Noor Haddad (Firmware platform + Mobile app)
REM-208Signed drug-library packages with version pinningAdopted
- Proposed (passed)
- Evaluating (passed)
- Adopted (current)
- Implementing (pending)
- Implemented (pending)
- Verified (pending)
TradeoffsCoverageDesign actionResidual effectCatalogObjectiveData and command integrity
ADOPTTomas Novak22 Apr 2026
Owner: Noor Haddad (Firmware platform)Target: FW 3.3.0 + LibraryManager 4.1Due: 19 Jun 2026DC-000318VOB-000215
REM-203Gateway network allowlist for command listenerdefense-in-depthAdopted
- Proposed (passed)
- Evaluating (passed)
- Adopted (current)
- Implementing (pending)
- Implemented (pending)
- Verified (pending)
TradeoffsCoverageDesign actionResidual effectCatalogObjectiveArchitecture change
ADOPTTomas Novak21 Apr 2026
Owner: Owen Blake (Gateway platform)Target: Gateway 2.5 (Q2 2026)Due: 29 May 2026DC-000316VOB-000213
REM-215Rate limiting and bounded queues on gateway command channelAdopted
- Proposed (passed)
- Evaluating (passed)
- Adopted (current)
- Implementing (pending)
- Implemented (pending)
- Verified (pending)
TradeoffsCoverageDesign actionResidual effectCatalogObjectiveAvailability resilience
ADOPTTomas Novak22 Apr 2026
Owner: Owen Blake (Gateway platform)Target: Gateway 2.5 (Q2 2026)Due: 26 Jun 2026DC-000321VOB-000218
REM-220Hash-chained tamper-evident audit segmentsAdopted
- Proposed (passed)
- Evaluating (passed)
- Adopted (current)
- Implementing (pending)
- Implemented (pending)
- Verified (pending)
TradeoffsCoverageDesign actionResidual effectCatalogObjectiveMonitoring accountability
ADOPTTomas Novak22 Apr 2026
REM-218Telemetry field-level redaction before uploadRejected
- Proposed (passed)
- Evaluating (passed)
- Rejected (blocked)
TradeoffsCoverageDesign actionResidual effectCatalogObjectiveConfidentiality privacy
REJECTTomas Novak23 Apr 2026
REM-219Tenant-scoped read tokens and mTLS on telemetry consumersAdopted
- Proposed (passed)
- Evaluating (passed)
- Adopted (current)
- Implementing (pending)
- Implemented (pending)
- Verified (pending)
TradeoffsCoverageDesign actionResidual effectCatalogObjectiveIdentity and access
ADOPTTomas Novak23 Apr 2026
REM-216Maintenance-mode auto-timeout with authenticated diagnosticsDeferred
- Proposed (passed)
- Evaluating (passed)
- Deferred (current)
TradeoffsCoverageDesign actionResidual effectCatalogObjectivePlatform hardening
DEFERDana Whitfield23 Apr 2026Interim control
Owner: Noor Haddad (Firmware platform)Target: FW 3.3.1 (Q4 2026)Due: 28 Aug 2026
- VOB-000211Authenticated-command fuzz testPending
- Methodology
- Protocol fuzzing of the signed command envelope (mutation + generation) against AE-000042 in HIL rig
- Acceptance criteria
- No unsigned/replayed/malformed frame reaches scheduling; rejected frames audited; zero crashes over 24 h corpus run.
- Environment
- Hardware-in-loop bench, FW 3.3.0-rc
- Evidence type
- Fuzz campaign report + coverage log
- VOB-000212Authentication-bypass penetration test on command pathPending
- Methodology
- Adversarial test of mutual-TLS enforcement, identity binding and authorization claims on DF-000077
- Acceptance criteria
- No unauthenticated or cross-device command accepted; findings at or below Low.
- Environment
- Staging ward segment with production-equivalent gateway
- Evidence type
- Penetration test report (independent tester)
- VOB-000213Allowlist enforcement and bypass-attempt alerting testPending
- Methodology
- Negative connection matrix from non-allowlisted subnets; alert pipeline verification
- Acceptance criteria
- 100% rejection of non-allowlisted peers; alert within 60 s.
- Environment
- Staging gateway 2.5
- Evidence type
- Test protocol + alert log extract
- VOB-000215Drug-library signature verification testIn progress
- Methodology
- Apply tampered/downgraded/unsigned libraries across activation paths
- Acceptance criteria
- All invalid libraries rejected pre-activation with audit event; valid library activates with hash record.
- Environment
- Bench pump + LibraryManager 4.1 beta
- Evidence type
- Verification protocol + device logs
- VOB-000218Gateway command-channel soak and flood testPending
- Methodology
- Sustained flood + slow-drip resource exhaustion against rate-limited listener
- Acceptance criteria
- Safety-priority lane p99 latency < 250 ms under flood; no queue exhaustion; shedding telemetry emitted.
- Environment
- Load rig, gateway 2.5-rc
- Evidence type
- Load test report
- VOB-000219Telemetry consumer scope enforcement testPending
- Methodology
- Cross-tenant/cross-site read attempts with mis-scoped and expired tokens; mTLS negative tests
- Acceptance criteria
- Zero cross-scope reads; all denials logged with principal.
- Environment
- Cloud staging, multi-tenant fixture
- Evidence type
- Authorization test matrix + access logs
- VOB-000220Audit-chain integrity verification testPending
- Methodology
- Truncate/rewrite/no-op mutations on log partition; chain verification on export
- Acceptance criteria
- Every mutation detected on verification; discontinuity alert raised.
- Environment
- Bench pump, FW 3.3.0-rc
- Evidence type
- Verification protocol + export tool output
- VOB-000108Service-port lockdown retestVerified
- Methodology
- Bench retest of serial shell access outside authenticated OPST-003 session
- Acceptance criteria
- No shell without authenticated service identity; sessions audited.
- Environment
- Bench pump, FW 3.1.4
- Evidence type
- Retest record EVA-000091