Security Reference Index
A single starting point for every API7 Gateway security and compliance page, including the reference material that lives outside this section, for security reviews and vendor questionnaires.
Security-relevant content for API7 Gateway isn't confined to this section. The detailed, field-level references for permission policies and infrastructure hardening live under Reference, organized there by kind of document (a reference page) rather than by topic (security). This page exists so that a security review, an audit, or a vendor security questionnaire has one link to start from instead of two directories to cross-check.
Nothing on this page is new content — every link below points at an existing page. Start with Security and Compliance Overview for the narrative walkthrough of the security model; use the tables below when you already know the topic you're looking for.
In this section
Security reference pages outside this section
These live under Reference because they're field-level reference material — the kind of page you look something up in, rather than read start to end — but they answer security questions as directly as anything above.
| Page | What it's for |
|---|---|
| Security Hardening Reference | Where sensitive information is stored across the control plane and data plane, how each category is encrypted or hashed, and the data_encryption keyring configuration and rotation procedure. Read this alongside Secure Credentials Management above — that page covers external secret managers, this one covers what API7 Gateway itself stores and how. |
| Permission Policy Actions and Resources | The full list of IAM actions and resource types available to write a permission policy against — the field-level companion to Permission Policies and Boundaries above. |
| Permission Policy Examples | Worked IAM policy examples grouped by common access-control scenario, using the actions and resources from the page above. |
| Ports and Endpoints | Every port a deployment listens on or connects to — the network surface a firewall review or penetration test needs. |
| Admin API Boundary Map | Which of the three admin-facing HTTP surfaces (Dashboard Admin API, Portal API backend, APISIX-native Admin API) applies to a given request, and why the one that's disabled by default is a materially different trust boundary if manually enabled. |
Related
- Security and Compliance Overview — the narrative introduction to the security model this page indexes.
- Version Support Policy — security-patch and maintenance coverage per release line, relevant to a vendor questionnaire's patching-cadence questions.