Skip to main content

FT-D-1 — Biometric endpoint flooded to exhaust FaceTec capacity

Component: Biometric Verification. Mitigations: Per-IP rate limit + concurrency semaphore (MaxConcurrentBiometric); 503 when full; 10 MB body cap. Action: None required.

PropertyValue
SectionDenial of Service
Ownerplatform

Mapped Controls

ControlTitle
SID-HARD-02Input Validation and Injection Prevention
SID-HARD-07Resource Upload Constraints

Source: STRIDE analysis (April 2026), architecture/stride-threat-model.md