Docs

Security Reference Index

A single starting point for every API7 Gateway security and compliance page, including the reference material that lives outside this section, for security reviews and vendor questionnaires.

Security-relevant content for API7 Gateway isn't confined to this section. The detailed, field-level references for permission policies and infrastructure hardening live under Reference, organized there by kind of document (a reference page) rather than by topic (security). This page exists so that a security review, an audit, or a vendor security questionnaire has one link to start from instead of two directories to cross-check.

Nothing on this page is new content — every link below points at an existing page. Start with Security and Compliance Overview for the narrative walkthrough of the security model; use the tables below when you already know the topic you're looking for.

In this section

Security reference pages outside this section

These live under Reference because they're field-level reference material — the kind of page you look something up in, rather than read start to end — but they answer security questions as directly as anything above.

PageWhat it's for
Security Hardening ReferenceWhere sensitive information is stored across the control plane and data plane, how each category is encrypted or hashed, and the data_encryption keyring configuration and rotation procedure. Read this alongside Secure Credentials Management above — that page covers external secret managers, this one covers what API7 Gateway itself stores and how.
Permission Policy Actions and ResourcesThe full list of IAM actions and resource types available to write a permission policy against — the field-level companion to Permission Policies and Boundaries above.
Permission Policy ExamplesWorked IAM policy examples grouped by common access-control scenario, using the actions and resources from the page above.
Ports and EndpointsEvery port a deployment listens on or connects to — the network surface a firewall review or penetration test needs.
Admin API Boundary MapWhich of the three admin-facing HTTP surfaces (Dashboard Admin API, Portal API backend, APISIX-native Admin API) applies to a given request, and why the one that's disabled by default is a materially different trust boundary if manually enabled.