Skip to content

M9-04 Security Hardening — DDoS Protection

Milestone: M9 — Hardening and Compliance SOW Reference: NFR3, Appendix 2 milestone description Requirement Clarity: 🟡 This only appears in the Appendix 2 milestone description text, not in the formal NFR3/Appendix 6 Security Requirements list — confirm it's still a hard requirement so it's covered by the Appendix 3 acceptance criteria Dev Status: ❌ Not started

Overview

Protect the platform against denial-of-service attacks, per the original v3 doc's standalone requirement ("DDoS protection must be in place") and the SOW's M7-M9 milestone description.

Backend Tasks

  • Confirm with Curo whether this is delivered via AWS-native services (Shield/CloudFront) once the AWS hosting target is decided (M4-01), or requires app-level mitigation too

Frontend Tasks

  • N/A

Dependencies

Acceptance Criteria

Not explicitly listed in Appendix 3 — worth adding an explicit criterion once scope is confirmed.

Existing Reference Material

None specific — general AWS security best practice.

Blockers & Risks

  • Needs decision: confirm this is still required given its absence from the formal requirements/acceptance-criteria lists.