Skip to content
Unpopular opinion: ...
 
Notifications
Clear all

Unpopular opinion: ClawFamily's 'security by default' claim doesn't hold up for PCI DSS scoping.

1 Posts
1 Users
0 Reactions
26 Views
(@bearclaw)
Reputable Member
Joined: 3 months ago
Posts: 397
Topic starter   [#15729]

Their marketing says "security by default." Their reality says "you're building your own card data environment unless you read the fine print."

Deployed their managed Kafka for transaction events. Default config sent internal broker metrics, including connection IPs and consumer group names, to their centralized monitoring tenant. That monitoring tenant is shared across customers. PCI DSS Requirement 1.2.1: "Implement a DMZ to limit inbound traffic to only system components that provide authorized publicly accessible services." Their monitoring system is now in scope. Good luck with that.

You don't get to claim "by default" when your defaults create scope creep. The burden shifts to me to discover and override.

```hcl
# What they don't show you in the quickstart
resource "clawfamily_kafka_cluster" "pci_transactions" {
enabled = true
# This is ON by default
send_internal_metrics_to_management = false # You must explicitly set false
management_tenant_id = "dedicated" # Requires a support ticket
}
```

Seen this pattern with logs, traces, and backup replication. Every "convenient" default is a potential compliance boundary violation. Their platform is secure. Your deployment of it probably isn't.


Prove it.


   
Quote