A risk management service.
Controlled disclosure was deferred to production on the reasoning that build mode has no users to expose. The first finding to arrive is a live authorization bypass in the service every other service trusts, where the choice today is publish or hold with nothing between. The deferral may still be right; it is now a decision with a real case in hand. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> |
||
|---|---|---|
| findings | ||
| INTENT.md | ||
| README.md | ||
risk-nexus
Risk register and regulatory intake for the estate. Serves
risk.coulomb.social. Owned by the-custodian.
Holds findings — security, architecture, operational, compliance — with a severity, an owner and a date; decides whether and when each is published; and decides which must reach the operator personally rather than sitting in a register.
It does not fix things: findings route to the repo that owns the defect. It
does not host: policy-nexus is the publication surface.
- Intent:
INTENT.md