CatalogueVPN-Poppy › Vendor security package

VPN-Poppy — vendor security package

com.vpnpoppy.desktop · version 0.1.11 · OllyDigital

This dossier is audit-ready evidence for the customer's own SOC 2, ISO 27001 or vendor-risk process, mapped to the SOC 2 Trust Services Criteria. It is not a certification — SOC 2 reports are issued only by a licensed CPA firm — and it documents the platform's cage around this poppy, not a code audit: the open source repository and the catalogue review exist for the code itself.

Every line below is generated from the reviewed package (sha256 3533cd67a4f5614fc6184045ef54c11fcfb43da475969d1e05c188f0db97c5bf) and the platform's own mechanisms — the same engines the app's permission screen uses. Security reports: support@agentspoppy.com (the poppy's support contact — a dedicated security contact arrives with its compliance declaration). A machine-readable copy of this document is at dossier.json.

Identity & provenanceCC1CC8.1

  • Enforced

    The reviewed artifact is content-addressed: package sha256 3533cd67a4f5614fc6184045ef54c11fcfb43da475969d1e05c188f0db97c5bf. The host verifies these exact bytes before installing, and every update is re-verified against the catalogue.

    Enforced at: broker package verification + catalogue sha256

  • Catalogue rule

    Source code is public at https://github.com/leonct74/VPN-Poppy — a listing condition, so the code this dossier describes can be audited by anyone, including the customer's own reviewers.

  • Enforced

    The package ships only the poppy's own code. The Node.js runtime is provided by the signed AgentsPoppy app from the official source — packages that embed a runtime or a service binary are refused at review and at install, because opaque bytes are exactly where a data-exfiltrating dependency would hide.

    Enforced at: RUNTIMES.md R1 — refused at pack, review and install

  • Enforced

    Its local backend runs confined by the host: no file access outside its own data folder, no child processes, no native code.

    Enforced at: backend.isolation strict — Node permission model

Access to the customer's cloudCC6

  • Enforced

    2 of its 3 permission grants are confined to the poppy's own resources; 1 reach beyond them (ec2). The approval preview lists each one, and the app shows the same lines before consent.

    Enforced at: assessor — computed from the reviewed manifest

  • Enforced

    It never holds your AWS keys. It gets a temporary session, minted for the job, that expires within 1 hour.

    Enforced at: broker aws/sts.ts — session duration is capped, not requested

  • Enforced

    That session can only ever be narrower than the role you installed. Nothing the broker issues can widen it.

    Enforced at: invariant I1 — IAM session-policy intersection

  • Enforced

    It can never manage the people in your account — no IAM users, no passwords or access keys, no MFA changes, and no account or organisation settings.

    Enforced at: broker role guardrails — an explicit Deny on the role itself

  • Enforced

    It can never hand itself administrator access by attaching AWS's admin policies to something it made.

    Enforced at: broker role guardrails — AdministratorAccess, IAMFullAccess, PowerUserAccess denied

  • Enforced

    Anything it creates is born carrying its own tag, or AWS refuses to create it.

    Enforced at: invariant I3 — an aws:RequestTag condition on every create

Change approvalCC5CC6.1

  • Enforced

    On by default: Every change waits for your approval, and an approval you do not answer expires after 15 minutes. Reads are not gated. The customer can switch supervision off per connection — keeping it on is listed under customer responsibilities below.

    Enforced at: broker service.ts — on by default for access outside the poppy's own resources

Where data can exitCC6.6CC7

  • Declared

    Declares its cloud code makes no internet connections.

  • Catalogue rule

    Cloud-code egress is a declaration: AWS provides no way for a platform to police where deployed code connects, and this dossier does not pretend otherwise. The declaration is what the catalogue review and the observed record are read against.

  • Catalogue rule

    Your servers, which it creates for you, can reach the internet. That is their purpose — what they send is what you put on them. Catalogue rules forbid a poppy from routing your cloud data or your activity out through infrastructure it creates.

Change managementCC8

  • Enforced

    Any change to its permissions in an update re-triggers user consent — the host asks again before the new scope applies, and the approval screen shows exactly what changed.

    Enforced at: host re-consent on permissionSet change

  • Catalogue rule

    Every new version passes mechanical review before it can enter or update the catalogue (manifest validated, package hashed, backend confinement and network declaration required); a version that changes grants is escalated for tiered review.

Monitoring & the recordCC7

  • Enforced

    It can never switch off CloudTrail — the record of what it did in your account.

    Enforced at: broker role guardrails — StopLogging, DeleteTrail and friends denied

  • Enforced

    Every change to this connection is written to a trail you can read.

    Enforced at: broker service.ts — getAudit

Removal & offboardingCC6.5

  • Enforced

    What it made stays findable even if this connection is replaced, so removing it later still finds everything.

    Enforced at: invariant I5 — ownership pinned to the app, not the connection

  • Enforced

    You can revoke this machine's operator key at any moment and cut every poppy off at once.

    Enforced at: broker service.ts — revokeOperatorKey

  • Enforced

    AWS refuses to create anything for it that isn’t labelled as its own, so “remove everything” finds all of it.

    Enforced at: invariant I3 — an aws:RequestTag condition on every create

  • Catalogue rule

    One click removes the poppy's cloud footprint: the stacks it created are deleted and a label sweep finds anything created outside them. The leaves-no-trace certification harness exercises exactly this lifecycle at review.

Platform governance & vendor accountabilityCC1CC9

  • Catalogue rule

    An undeclared data flow found after listing means immediate delisting; a deceptive declaration — data covertly read, copied or transmitted — means permanent removal, the developer account closed, and the poppy blocklisted so existing installs are warned.

  • Catalogue rule

    Where user data reaches a service the developer operates, the developer must declare the flow and maintain a privacy policy covering it, and AgentsPoppy may require audit access to the receiving service's source code as a condition of listing.

Developer declarationsCC9

  • Catalogue rule

    This version was packaged before the compliance declaration existed (September 2026). The catalogue requires the declaration — what data it handles, its subprocessors, a security contact — at the poppy's next update.

Customer responsibilities (complementary controls)CC6CC7

  • Customer control

    Keep supervision on for connections to production accounts, and answer approval requests deliberately.

  • Customer control

    Review the connection's record and approval history periodically — the record is the customer's evidence of operating effectiveness.

  • Customer control

    Treat a permission-change re-consent screen as a change-control decision, not a click-through.

  • Customer control

    Keep CloudTrail enabled account-wide. The platform prevents poppies from switching it off, but enabling it is the account owner's control.

  • Customer control

    Restrict who in the organisation can install poppies and hold the operator key; revoke the key when a machine leaves service.

Assessing VPN-Poppy in depth? The source code is public at github.com/leonct74/VPN-Poppy, and the listing page shows the exact approval screen the app will present. Platform-wide guarantees are documented on the security page.