docs(security): state the at-rest and provider-visibility threat model - #127
docs(security): state the at-rest and provider-visibility threat model#127dmnyc wants to merge 2 commits into
Conversation
|
@claude review |
|
Claude finished @dmnyc's task in 3m 24s —— View job Review:
|
|
Review feedback addressed in 46dd65d — every finding, since a security policy only works if every sentence is true of the shipped build:
|
Fixes #115 (M-6, M-7, L-10, L-15).
SECURITY.md now says plainly what the codebase actually guarantees: a profile reader gets the descriptor (all addresses + SLIP-77, secret-equivalent, not 'watch-only'), the scan history, and metadata; chain-data providers see and can cluster the address set (with the self-hosted Esplora escape hatch); SideSwap sees the swapped asset's UTXOs with blinding factors; registry asset labels are issuer-steerable display hints. Sits next to the existing 'no telemetry' statement so the honest caveat travels with the claim. Links the 2026-08 scan.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.