StackAttestTechnical Trust
StackAttest Core 1.0

The control catalogue

13 controls, each one a question with a defined way of being answered. For every control: what it evaluates, how a result is established, the weakest evidence that can pass it, and the external clauses it maps to.

6 of them are production gates. A failing gate is not averaged away by strong results elsewhere, which is the difference between a score and an average.

security

What separates users, data and privileged actions from everybody else.

SA-CORE-001highproduction gate

Transport security (TLS) is enforced

Established by:
runtime probe, configuration inspection
Passes at:
E2 or better, which is source verified
Mapped to:
OWASP ASVS 5 v5.0.0-12.1, v5.0.0-12.2 · NIST SSDF PW.9 · CWE CWE-319, CWE-295 · OWASP API Security Top 10 API8:2023 · WSTG WSTG-CRYP
SA-CORE-002medium

Security response headers are present

Established by:
runtime probe
Passes at:
E4 or better, which is runtime verified
Mapped to:
OWASP ASVS 5 v5.0.0-3.4 · NIST SSDF PW.9 · CWE CWE-693, CWE-1021 · OWASP API Security Top 10 API8:2023 · WSTG WSTG-CONF
SA-CORE-003highproduction gate

Authentication endpoints are rate limited

Established by:
runtime probe, source trace
Passes at:
E3 or better, which is deterministically tested
Mapped to:
OWASP ASVS 5 v5.0.0-6.3.1 · NIST SSDF PW.5 · CWE CWE-307, CWE-799 · OWASP API Security Top 10 API4:2023 · WSTG WSTG-ATHN
SA-CORE-004criticalproduction gate

Object ownership is enforced server-side

Established by:
source trace, runtime authorisation test
Passes at:
E2 or better, which is source verified
Mapped to:
OWASP ASVS 5 v5.0.0-8.2.2 · NIST SSDF PW.1, PW.5 · CWE CWE-639, CWE-862 · OWASP API Security Top 10 API1:2023, API5:2023 · WSTG WSTG-ATHZ
SA-CORE-005high

Server-side input validation on state-changing endpoints

Established by:
source trace
Passes at:
E2 or better, which is source verified
Mapped to:
OWASP ASVS 5 v5.0.0-2.2 · NIST SSDF PW.5 · CWE CWE-20 · OWASP API Security Top 10 API3:2023 · WSTG WSTG-INPV
SA-CORE-006criticalproduction gate

Injection-safe data access

Established by:
source trace, deterministic test
Passes at:
E2 or better, which is source verified
Mapped to:
OWASP ASVS 5 v5.0.0-1.2.4, v5.0.0-1.2.5 · NIST SSDF PW.5 · CWE CWE-89, CWE-78 · WSTG WSTG-INPV
SA-CORE-007criticalproduction gate

Secrets are managed outside source code

Established by:
secret scan
Passes at:
E3 or better, which is deterministically tested
Mapped to:
OWASP ASVS 5 v5.0.0-13.3.1 · NIST SSDF PS.1, PW.5 · CWE CWE-798, CWE-540 · WSTG WSTG-CONF
SA-CORE-008medium

Error responses do not leak internals

Established by:
runtime probe, source trace
Passes at:
E3 or better, which is deterministically tested
Mapped to:
OWASP ASVS 5 v5.0.0-16.5 · NIST SSDF PW.5 · CWE CWE-209 · OWASP API Security Top 10 API8:2023 · WSTG WSTG-ERRH
SA-CORE-012high

Dependencies are free of known-critical vulnerabilities

Established by:
dependency scan
Passes at:
E3 or better, which is deterministically tested
Mapped to:
OWASP ASVS 5 v5.0.0-15.2.1 · NIST SSDF PW.4 · CWE CWE-1395, CWE-1104 · SLSA provenance

reliability

Whether the system can be brought back after it goes wrong.

SA-CORE-010criticalproduction gate

Verified backups and restore procedure

Established by:
configuration inspection, operator attestation, restore test
Passes at:
E2 or better, which is source verified
Mapped to:
NIST SSDF PO.5

operations

Whether a failure is noticed, and whether a bad change can be undone.

SA-CORE-011medium

Health checks and basic observability

Established by:
runtime probe, configuration inspection
Passes at:
E2 or better, which is source verified
Mapped to:
OWASP ASVS 5 v5.0.0-16.2, v5.0.0-16.3 · CWE CWE-778
SA-CORE-013medium

Deployment rollback path exists

Established by:
configuration inspection, operator attestation
Passes at:
E2 or better, which is source verified
Mapped to:
NIST SSDF PO.4, PW.9

performance

Whether the behaviour that works today survives more of everything.

SA-CORE-009high

Database queries are index-backed at scale

Established by:
schema inspection, query plan analysis
Passes at:
E2 or better, which is source verified
Mapped to:
CWE CWE-1049 · OWASP API Security Top 10 API4:2023

What this page does not publish

Weights, thresholds, the scoring arithmetic, and the exact pass, partial and fail criteria stay in the pack. Publishing what is evaluated and how a result is established is what makes a score inspectable. Publishing the arithmetic would not make a reader better informed, and it would make the result easier to aim at than to satisfy.

Deeper packs extend this set per application risk profile. This page describes StackAttest Core 1.0, which is the baseline that applies to virtually every web and API product.

Mapping is not certification

A mapping means a StackAttest control references a clause in that external vocabulary. It is not a claim that StackAttest, or any product it validates, is certified, accredited, approved or reviewed by OWASP, NIST, MITRE or anybody else. None of those organisations endorses this work. Evidence toward a practice is not conformance with it, and a control that maps to an ASVS clause does not award an ASVS level.

Keep reading