# risk-nexus Risk register and regulatory intake for the estate. Serves `risk.coulomb.social`. Owned by `the-custodian`. Holds findings — security, architecture, operational, compliance — with a severity, an owner and a date; decides whether and when each is published; and decides which must reach the operator personally rather than sitting in a register. It does not fix things: findings route to the repo that owns the defect. It does not host: `policy-nexus` is the publication surface. - Intent: `INTENT.md`