Static Public
Public content with no write path. Automated checks and deployment controls.
Risk classification determines rigor. Compliance defines obligations. Approval is scoped to a system version, evidence package, owner, environment, and review date.
Risk classes
The system class changes when architecture changes. Adding a form, database, user account, trading endpoint, or payment is a security event—not merely a feature.
Public content with no write path. Automated checks and deployment controls.
Forms, comments, or low-risk APIs. Security review and abuse controls.
Accounts, databases, private data, and write APIs. Formal security approval.
Trading, payment, deletion, and privileged operations. Human gate and independent review.
Cross-cutting governance
Identity, permission, evidence, audit, incident response, privacy, licensing, retention, and recovery govern both frontend and backend systems.
Every material risk, exception, control and alert has a named accountable owner and review date.
Data license, privacy, retention, access, redistribution, disclosure, and system obligations are explicit.
Controls produce version-scoped evidence; privileged actions remain attributable and reviewable.
Detect, triage, contain, eradicate, recover, and learn with evidence preservation.
Known-good artifacts, backup restore, rollback, fallback, kill switch, and operational ownership.
External communication, deletion, payment, trading, and permission expansion require explicit approval.
Security promotion
Material architecture changes or control failures invalidate affected approvals and return the system to review.