risk-nexus/docs/verifications/2026-09-05-open-findings-source-review.md
tegwick bbbede5f47 Keep review obligations visible and reconcile owner evidence (RISK-WP-0006, RISK-WP-0007)
check_all runs every check stage even when one fails; malformed dates are
reported rather than aborting; accepted findings and closure evidence are
shown; defer requires a valid future date. Adds SCOPE.md, the scope
assessment, the open-findings source review and a unittest suite. Stops
tracking __pycache__.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 6903@bnt-lap001
Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
2026-09-22 07:56:58 +02:00

5.6 KiB

id type title date owner workplan findings
RISK-V-0003 verification Owner-source progress and outstanding runtime evidence 2026-09-05 risk-nexus RISK-WP-0007
RISK-F-0011
RISK-F-0010
RISK-F-0008

Owner-source review — 2026-09-05

This is a checkout and inbox review, not a runtime probe. No credentials were used or reproduced, no system was changed and no legal determination was renewed. Files can include uncommitted owner work; repository HEAD is context, not proof that every inspected change is in that commit.

Qonto deny-stream completeness

Read State Hub notice c6442eef-34fc-46a7-9639-10f2cd6120fc (2026-09-04), QONTO-WP-0005, specs/audit-emission-cadence.yaml, src/qonto_assistant/audit.py, the application lifespan/reconciliation endpoint, and KG-WP-0005.

The source now declares process instance/sequence semantics, a 24-hour default active-process heartbeat, startup and best-effort shutdown, and reconciliation counts. AuditLogger serializes emission and exposes source counters; the app wires the heartbeat lifecycle and identity-checked snapshot route. Qonto records 88 passing tests on its latest review; that suite was not rerun by risk-nexus. King's Guard records local source-path validation and explicitly leaves KG-WP-0005-T03 waiting for authorized deployed evidence.

Conclusion: the old statement that no source cadence/reconciliation exists is obsolete. Runtime completeness remains unestablished. F-0011 stays open, medium and public, with QONTO-WP-0005 and KG-WP-0005-T03 as tracking.

Closure evidence owed: qonto's runtime owner supplies a bounded capture from one deployed instance, naming the deployed revision, configured heartbeat interval and observation window. It covers startup, a request transition, periodic heartbeat timing, sequence/instance continuity and a same-instance reconciliation snapshot. King's Guard compares received counts and source counts, records any gaps and the acceptance decision. Evidence may support only the observed instance/window, never an unbounded all-time completeness claim. The original 2026-09-16 default remains; a completed source plan does not close the runtime finding. This narrows the existing evidence request; no new request or message was sent in this sitting.

Backup credential

Read RPF-WP-0029 and inspected tools/cmd/forgejo-backup in memory for the named shell fallback without outputting credential-bearing lines. No nonempty literal fallback for RAILIANCE_BACKUP_NC_TOKEN remains in that script. The owner records fail-closed input tests as complete under T01. T02 is wait: provider-side invalidation and encrypted upload/restore receipts are absent.

Conclusion: source removal is established in the checkout; predecessor invalidation is not. F-0010 stays open, low and embargoed. RPF-WP-0029-T02 names the remaining provider/recovery work. The 2026-09-15 embargo review/default stands. No inference is made about whether the predecessor is still valid. Only non-secret invalidation, governed ciphertext upload and restore receipts can complete the remaining evidence; source removal alone cannot lift the hold.

Accepted retention obligation

Read the existing acceptance and determination references in F-0008 and audit-core/docs/erasure-and-audit.md. Audit Core still documents the cleartext-hash confirmation problem and says keyed commitments are not built. No new answer to the co-residency horizon or keyed-commitment wait was present in the fetched risk-nexus inbox. This is not proof that no answer exists elsewhere.

F-0008 already has a named accepter, an ending condition, a real determination and a next check. The reporting problem is classifying that accepted obligation as an untracked fix. The report should expose its existing acceptance terms without inventing engineering work or treating acceptance as closure. Its substantive review remains due: this sitting does not establish that the real-person/counterparty trigger has not fired and does not renew the legal basis.

External intake and scheduled reviews

Searched policy-nexus publication configuration, workplans and deployment files for a security contact/security.txt or delivered external-report route. None was found in those inspected sources. The existing intake proposal remains the available evidence; current public endpoints and estate-wide contact availability were not verified. Publishing a new contact requires its actual receiving owner.

Searched activity-core's local definitions and evidence for the two risk register activities. No matching execution receipt was found in those paths. The two definitions in risk-nexus remain source instructions. Their live registration, execution and completed-session chain are unverified; this search is not proof that the activities do not run. No deployment or synchronization was attempted.

Source provenance

Inspected source SHA-256 of the non-secret document
qonto-assistant QONTO-WP-0005 f3b21ed7d046e7a4e5e8eee1397dcdcf1a17211f75786da3a0a2258b44802c3a
qonto-assistant cadence declaration 69db6068b2e262f6b9108903cf7c5a7764efba5c981344c50df496018bc98ed9
qonto-assistant audit.py 573e669914ae2ae77dfbf0a0929ef080cfbcb7dd4e0ba79e9408dd401fd74437
railiance-platform RPF-WP-0029 396d2e167b8bd1141671fadd864660a1e8bc6efb1ea3a09be3465e841ce33144
audit-core erasure-and-audit.md 40d0f86ad401c3fb413fb21346a77210b6840d52f05093b31143a11b8a3a878b

Observed HEADs: qonto e5611147fd72a23e58618b87b0c3b96c807d0043, railiance-platform f637989a6911a7a13812cba223ffc007d78d6302, audit-core 95dcb78e17d46889c17b55e3ba1aadbcceec6a99, policy-nexus c1b60f322e3bcddff3cece618ece2bd3686169e1.