Write the end-to-end photo data-flow threat model #20

Open
opened 2026-08-19 01:58:59 +00:00 by timmy · 0 comments
Owner

Parent epic: #5

Outcome

Make sensitive-data boundaries and abuse cases explicit before beta.

Acceptance criteria

  • Diagram covers browser, API, model worker, transient buffers, training opt-in store, logs, exports, and deletion.
  • Threats include replay, oversized input, metadata leakage, poisoning, unauthorized training, and operator access.
  • Mitigations have owners and testable follow-up tickets.

Dependencies

  • None

Required evidence

  • Test or executable receipt attached to the issue/PR
  • Privacy/safety boundary checked where applicable
  • Clean checkout and relevant full suite pass

Delivery

Open a focused branch and PR with Closes #ISSUE. Do not include real medical images in issue comments or Git history.

Parent epic: #5 ## Outcome Make sensitive-data boundaries and abuse cases explicit before beta. ## Acceptance criteria - [ ] Diagram covers browser, API, model worker, transient buffers, training opt-in store, logs, exports, and deletion. - [ ] Threats include replay, oversized input, metadata leakage, poisoning, unauthorized training, and operator access. - [ ] Mitigations have owners and testable follow-up tickets. ## Dependencies - None ## Required evidence - Test or executable receipt attached to the issue/PR - Privacy/safety boundary checked where applicable - Clean checkout and relevant full suite pass ## Delivery Open a focused branch and PR with `Closes #ISSUE`. Do not include real medical images in issue comments or Git history.
timmy added this to the M1 — Sovereign Photo Intelligence milestone 2026-08-19 01:58:59 +00:00
timmy added the
type/security
priority/P0
area/privacy
labels 2026-08-19 01:58:59 +00:00
Sign in to join this conversation.
No project
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: stackchain/timmy-talking-turd#20
No description provided.