Skip to content

S8 — Trust pack: threat model, privacy, security, CRA, comparison #20

Description

@fmind

What a stranger gets: honest security answers before they ask — and a comparison page that concedes first.

Acceptance

  1. docs/security/threat-model.md with both admissions stated plainly: a4h holds the organization's chat bot token; a4h cannot prevent prompt injection — plus the blast-radius story.
  2. PRIVACY.md ("nothing is persisted; the project receives no data from your deployment"), SECURITY.md (private vulnerability reporting, 5-working-day acknowledgement), docs/compliance/cra.md including the consulting paragraph.
  3. docs/compare.md verified cell by cell against the competitors' own documents in the publication hour (the Hermes A2A cell carries an inline re-check note); concede-first voice; the forbidden-claims grep is green.
  4. Published in the same hour as the v0.1 tag, never before.

Non-goals

Badge campaigns · conformance matrices · enterprise questionnaire packs.

Runs in parallel with the code slices — docs only.

Metadata

Metadata

Assignees

No one assigned

    Labels

    docsEnd-user documentation and sitesecuritySecurity, privacy, compliance

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions