# Security Core

> The rules governing security posture — no hardcoded secrets, validated input, least privilege, no insecure fallbacks.

Record: `algorithms:security-core`
Kind: algorithm
Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)
Canonical: https://banes-lab.com/ontology/algorithms#algorithms-security-core
Closure: https://banes-lab.com/json/records/algorithms/security-core/closure

Listed in [Algorithm contracts](https://banes-lab.com/api/records/algorithms.md), after [Computation Core](https://banes-lab.com/records/algorithms/computation-core.md) and before [Performance Core](https://banes-lab.com/records/algorithms/performance-core.md).

## Domain

- [Architectural Clusters](https://banes-lab.com/records/algorithms-domain/architectural-clusters.md)

## Tier

- [exempt](https://banes-lab.com/records/vocabulary/domain-tier-exempt.md)

## Principle

- [Security by Design](https://banes-lab.com/records/architecture/security-by-design.md)

## Composed by

- [Secret Store Over Hardcoded Secrets](https://banes-lab.com/records/algorithms/no-hardcoded-secrets.md)
- [Boundary Validation Over Unvalidated Input](https://banes-lab.com/records/algorithms/no-unvalidated-input.md)
- [Least Privilege Over Broad Privilege](https://banes-lab.com/records/algorithms/no-broad-privilege.md)
- [Config Externalization Over Env Fallback](https://banes-lab.com/records/algorithms/no-env-fallback.md)

## Contract of

- [Security Core](https://banes-lab.com/records/layer/security-core.md)

## Linked from

- [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- [Architectural Rules](https://banes-lab.com/ontology/algorithms/algorithms-domain-architectural-rules.md)
- [Domain tiers](https://banes-lab.com/ontology/schema/the-vocabulary-domain-tier.md)
- [The layer topology](https://banes-lab.com/ontology/schema/the-layer-topology.md)
