Skip to content

[CA-01-S6] Document Echo security posture and threat models #667

Description

@flyingrobots

Goal

Publish an evidence-grounded security topic set that states what Echo protects, which components and identities it trusts, which attackers and failures it considers, how current controls map to those threats, and where the implementation deliberately makes no security claim.

Acceptance criteria

  • docs/topics/security/README.md defines the security posture, protected assets, trust boundaries, security properties, and documentation map.
  • docs/topics/security/ThreatModel.md enumerates attacker capabilities, abuse cases, mitigations, residual risks, and explicit non-goals across application proposals, trusted-host admission, WAL and durable storage, CAS and projections, Continuum transport, observer capabilities, recovery, replay, downgrade, corruption, and resource exhaustion.
  • docs/topics/security/AuthorityBoundaries.md distinguishes causal authority, cryptographic integrity, authorization, confidentiality, durability, availability, and derived evidence; no checksum, digest, receipt, WAL record, cache, or materialization is overstated as proof beyond its actual proposition.
  • Claims identify current implementation evidence versus architectural requirements or open gaps and link to the relevant topic, ADR, code, or executable witness.
  • Mermaid trust-boundary and threat-flow diagrams render successfully; Markdown validation passes.
  • docs/README.md and docs/topics/README.md link the security topic set.

Activity

  1. added
    enhancementNew feature or request
    taskSmall, 1–3h task
    specSpec/Design document
    coreEcho Core Technologies
    work-in-progressSomeone is actively working this issue.
    release:echo-1.0Echo 1.0 release convergence scope
    on Jul 14, 2026
  2. coderabbitai commented on Jul 14, 2026

    @coderabbitai
    Contributor
    🔗 Related PRs

    #546 - Adopt braids and strands hardening roadmap [closed]
    #582 - docs: define the Echo 1.0 release contract and move live planning to GitHub [merged]


    📝 Issue Planner

    Check the box below or use the @coderabbitai plan command to generate an implementation plan and prompts that you can use with your favorite coding assistant.

    • Create Plan

    🧪 Issue enrichment is currently in open beta.

    You can configure auto-planning by selecting labels in the issue_enrichment configuration.

    To disable automatic issue enrichment, add the following to your .coderabbit.yaml:

    issue_enrichment:
      auto_enrich:
        enabled: false

    💬 Have feedback or questions? Drop into our discord!

  3. flyingrobots commented on Jul 15, 2026

    @flyingrobots
    OwnerAuthor

    Implemented in e9a12b0. The security topic set documents protected assets, trust boundaries, threat actors, mitigations, residual risks, non-goals, authority distinctions, and current evidence across admission, WAL, CAS/projections, exchange, recovery, and resource exhaustion.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    coreEcho Core TechnologiesenhancementNew feature or requestfeatureFeature umbrella (epic)lane:up-nextMethod lane up-next.legend:platformMethod legend platform.legend:testMethod legend test.priority:highMethod priority high.release:echo-1.0Echo 1.0 release convergence scoperuntimeRuntime corespecSpec/Design documenttaskSmall, 1–3h tasktoolingTooling/CI/CLItype:enhancementMethod work type enhancement.work-in-progressSomeone is actively working this issue.

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions