Home/Security
Threat model · as of September 2026
Security of the write, not security of the chat
What can go wrong at the write.
None of these threats has had adversarial security testing.
T1 Unsupported write with permission
TestedA scribe role may call update_note. The model emits “left TM perforated” with no exam. Permission was sufficient. Evidence was not.
Construction refused — Tested. Permission-only stacks still allow it.
T2 Injection after review
Not defendedText in a transcript or attachment is quoted as evidence. The engine checks that evidence exists, not that it supports the value.
T3 Approve-then-swap
ProposedClinician approves wording A. Agent commits wording B.
Designed control: payload_hash. Kernel does not currently bind approval to bytes.
T4 Silent drop of refusal
TestedConstruction fails and the UI hides it. The clinician never learns the model tried to write a perforation.
Refusal can be surfaced. Still a product risk if a caller swallows it.
T5 No replay
OpenAfter the fact, nobody can reconstruct which payload was decided.
No durable audit module. In-memory draft versioning is not a log.
Controls, mapped to clinic.
- Tested
Typed claim
The chart does not receive a paragraph of model prose. It receives concept + value.
- Tested
Evidence required to construct
No source → no finding object.
- Tested
Refusal stays visible
The clinician sees the attempt. Nothing is quietly omitted.
Presentation path.
- Proposed
Hash-bound approval
The person approved these bytes. Mutation → APPROVAL_HASH_MISMATCH.
- Open
Append-only decision log
A later reviewer can replay what was decided.
- Built
Policy version on the object
You can see which vocabulary ran.
Registry built. Clinical content unverified.
Named gaps.
Approver identity is a string. Nothing authenticates the caller.
Not defendedpayload_hash binding is specified, not enforced.
ProposedAttachment is not support. A quote can be wrong.
Not defendedNo persistence layer. Durability is not a property this kernel provides.
OpenNo standalone gateway service. Callers can bypass the gate.
OpenNo adversarial testing. Happy-path tests are not a red team.
Not defendedENT schema not clinician-verified.
Open
Designed for clinical systems of record; not certified for production use.