Status Approved. Reviewer: Diego Ortega.
Production VPCs are fully isolated from development and corporate networks. Private subnets host data tier; only a small set of bastion hosts reach the private tier and require MFA + just-in-time access grants. Egress is restricted via VPC endpoints and explicit allow-lists.
Production VPCs are fully isolated from development and corporate networks. Private subnets host data tier; only a small set of bastion hosts reach the private tier and require MFA + just-in-time access grants. Egress is restricted via VPC endpoints and explicit allow-lists.
Rationale: AI-matched against LIB-SEC-014; reviewed verbatim.
Verified against trust portal documentation; no changes.