Skip to main content

Asset Inventory

Organization: JE Vectors LLC (product: Nquiry) Last Updated: 2026-02-04 Owner: Security Officer

This document maintains an inventory of all information assets for compliance with HIPAA, FedRAMP, and SOC 2 requirements.


1. Infrastructure Assets

1.1 AWS Services

Asset IDServicePurposeData ClassificationRegionOwner
AWS-001AWS ECS FargateApplication hostingConfidentialus-east-1DevOps
AWS-002Amazon RDS PostgreSQLPrimary databaseConfidential/PHIus-east-1DevOps
AWS-003Amazon S3Evidence file storageConfidential/PHIus-east-1DevOps
AWS-004Amazon CognitoUser authenticationConfidentialus-east-1DevOps
AWS-005AWS BedrockAI analysisConfidential/PHIus-east-1DevOps
AWS-006Amazon ElastiCacheRate limiting (Redis)Internalus-east-1DevOps
AWS-007AWS CloudWatchMonitoring & loggingInternalus-east-1DevOps
AWS-008AWS Secrets ManagerCredential storageConfidentialus-east-1DevOps
AWS-009AWS KMSEncryption key managementConfidentialus-east-1DevOps
AWS-010AWS VPCNetwork isolationInternalus-east-1DevOps
AWS-011Amazon ECRContainer image registryInternalus-east-1DevOps
AWS-012Amazon ALBLoad balancing & TLSConfidentialus-east-1DevOps
AWS-013Amazon CloudFrontCDN & TLS terminationConfidentialus-east-1DevOps
AWS-014Amazon Route53DNS managementInternalus-east-1DevOps
AWS-015AWS ACMTLS certificate mgmtConfidentialus-east-1DevOps
AWS-016AWS IAM (OIDC)GitHub Actions CI/CD authInternalus-east-1DevOps

1.2 Third-Party Services

Asset IDServicePurposeData ClassificationOwner
SVC-001StripePayment processingPCI (no PHI)Finance
SVC-002SentryError trackingInternalDevOps
SVC-003GitHubSource code repositoryConfidentialDev

2. Application Assets

2.1 Source Code Repositories

Asset IDRepositoryDescriptionClassificationAccess
REPO-001investigation-appMain applicationConfidentialDev team

2.2 Application Components

Asset IDComponentDescriptionTechnologyData Access
APP-001Web ApplicationUser interfaceNext.js 16All user data
APP-002API RoutesBackend endpointsNext.js APIAll user data
APP-003AI Analysis EngineClaude integrationAWS BedrockInvestigation data
APP-004Auth SystemUser authenticationCognito + customUser credentials
APP-005Audit SystemCompliance loggingCustomAll actions

3. Data Assets

3.1 Database Tables

Asset IDTableDescriptionClassificationRetention
DB-001organizationOrganization recordsInternalIndefinite
DB-002organization_memberMembership recordsInternalIndefinite
DB-003user_profileUser profilesConfidentialPer GDPR
DB-004investigationInvestigation recordsConfidential/PHI7 years
DB-005evidenceEvidence itemsConfidential/PHI7 years
DB-006evidence_attachmentFile metadataConfidential/PHI7 years
DB-007topicInvestigation topicsConfidential/PHI7 years
DB-008questionInvestigation questionsConfidential/PHI7 years
DB-009analysisAI-generated analysisConfidential/PHI7 years
DB-010reportGenerated reportsConfidential/PHI7 years
DB-011audit_logAudit trailConfidential7 years
DB-012billing_subscriptionBilling recordsPCI/Confidential7 years

3.2 File Storage (S3)

Asset IDBucketContentClassificationRetention
S3-001evidenceUser-uploaded evidenceConfidential/PHI7 years
S3-002framework-documentsReference documentsConfidentialIndefinite

3.3 Logs

Asset IDLog TypeLocationClassificationRetention
LOG-001Application logsCloudWatchInternal90 days
LOG-002Audit logsRDS (audit_log)Confidential7 years
LOG-003Access logsS3 access logsInternal90 days
LOG-004VPC flow logsCloudWatchInternal90 days

4. Cryptographic Assets

4.1 Encryption Keys

Asset IDKey TypePurposeManagementRotation
KEY-001RDS encryption keyDatabase encryption at restAWS KMSAnnual
KEY-002S3 encryption keyFile encryption at restAWS KMSAnnual
KEY-003MFA encryption keyTOTP secret encryptionSecrets ManagerOn compromise
KEY-004Session signing keyJWT/session tokensCognito managedAutomatic

4.2 Certificates

Asset IDCertificatePurposeIssuerExpiration
CERT-001*.amplifyapp.comTLS for stagingAWSAuto-renewed
CERT-002app.nquiry.aiTLS for productionAWS ACMAuto-renewed

5. Access Credentials

5.1 Service Accounts

Asset IDAccountPurposeStorageRotation
CRED-001RDS adminDatabase administrationSecrets ManagerQuarterly
CRED-002S3 accessFile operationsIAM roleN/A
CRED-003Bedrock accessAI API callsIAM roleN/A
CRED-004Stripe API keysPayment processingEnv varsAnnual
CRED-005Sentry DSNError reportingEnv varsOn compromise

5.2 User Accounts (Administrative)

Asset IDAccount TypePurposeMFA Required
ADMIN-001AWS rootEmergency accessYes
ADMIN-002AWS IAM adminInfrastructure managementYes
ADMIN-003GitHub adminRepository managementYes
ADMIN-004Stripe adminBilling managementYes

6. Network Assets

6.1 VPC Configuration

Asset IDComponentCIDRPurpose
NET-001VPC10.0.0.0/16Isolated network
NET-002Public subnets10.0.1.0/24, 10.0.2.0/24Load balancers, NAT
NET-003Private subnets10.0.10.0/24, 10.0.20.0/24RDS, ElastiCache

6.2 Security Groups

Asset IDGroupInboundOutboundAssociated Resources
SG-001rds-sg5432 from VPCAllRDS instance
SG-002redis-sg6379 from VPCAllElastiCache
SG-003amplify-sg443 from internetAllAmplify compute

7. Documentation Assets

Asset IDDocumentPurposeClassificationLocation
DOC-001HIPAA Risk AssessmentComplianceConfidentialdocs/admin/security/
DOC-002Security Remediation PlanTrackingConfidentialdocs/
DOC-003Pre-Launch ChecklistVerificationInternaldocs/
DOC-004Data DictionarySchema referenceInternaldocs/
DOC-005Incident Response PlanSecurityConfidentialdocs/admin/security/

8. Asset Classification Guide

ClassificationDescriptionHandling Requirements
PublicInformation that can be freely sharedNo restrictions
InternalBusiness information for internal useAccess control required
ConfidentialSensitive business informationEncryption, access logging
Confidential/PHIMay contain protected health informationHIPAA safeguards required
PCIPayment card informationPCI-DSS compliance required

9. Change Log

DateAsset IDChangeAuthor
2026-02-04AllInitial inventoryClaude (AI)

10. Review Schedule

  • Monthly: Review access credentials, check for unused assets
  • Quarterly: Full inventory review, update classifications
  • Annually: Complete asset audit, verify retention compliance