Security Department for the Pengyi System

We protect what Pengyi builds.

Security, risk, and compliance engineered into every website, API, dataset, agent, MCP server, and future trading system—from first design to production recovery.

Current security register

Transparent by design.

These numbers describe the current security framework—not a claim that future systems are already production-secure.

2Primary security planes
4System risk classes
9Baseline control families
1Registered protected system

Security lifecycle

Protection is a state machine.

A document is not a control, and a configuration is not proof. Every release moves through implementation, verification, approval, monitoring, and revocation paths.

01 / DEFINEThreat Model
02 / BUILDControls
03 / PROVEEvidence
04 / OPERATEMonitor & Recover

First protected system

PENGYIDATA.

A static Cloudflare Pages site today; a governed data platform tomorrow. Its risk class rises automatically when forms, accounts, databases, APIs, or trading actions appear.

SystemCurrent classArchitecturePriorityProduction writes
PENGYIDATAS0Static frontendHeaders · IAM · DeploymentNone
Future accounts/APIS2 plannedBackend + databaseAuthZ · Abuse · AuditHuman gate
Future tradingS3 plannedCapital-bearing systemLimits · Kill switch · ReviewIndependent approval