Trust requires evidence.

Risk classification determines rigor. Compliance defines obligations. Approval is scoped to a system version, evidence package, owner, environment, and review date.

Risk classes

Controls rise with consequence.

The system class changes when architecture changes. Adding a form, database, user account, trading endpoint, or payment is a security event—not merely a feature.

S0

Static Public

Public content with no write path. Automated checks and deployment controls.

S1

Interactive

Forms, comments, or low-risk APIs. Security review and abuse controls.

S2

Private State

Accounts, databases, private data, and write APIs. Formal security approval.

S3

Capital & Privilege

Trading, payment, deletion, and privileged operations. Human gate and independent review.

Cross-cutting governance

One control language.

Identity, permission, evidence, audit, incident response, privacy, licensing, retention, and recovery govern both frontend and backend systems.

GOV-001

Risk Ownership

Every material risk, exception, control and alert has a named accountable owner and review date.

GOV-002

Compliance Mapping

Data license, privacy, retention, access, redistribution, disclosure, and system obligations are explicit.

AUD-001

Evidence & Audit

Controls produce version-scoped evidence; privileged actions remain attributable and reviewable.

IR-001

Incident Response

Detect, triage, contain, eradicate, recover, and learn with evidence preservation.

BCP-001

Recovery

Known-good artifacts, backup restore, rollback, fallback, kill switch, and operational ownership.

HR-001

Human Gates

External communication, deletion, payment, trading, and permission expansion require explicit approval.

Security promotion

Approval can be revoked.

Material architecture changes or control failures invalidate affected approvals and return the system to review.

01Designed
02Implemented
03Verified
04Approved & Monitored