Investment Plans workspace
Open raw ↗

THREAT MODEL AND DEFENCE REVIEW

OWNER: 01_System/build_handover.py REVIEW: regenerate whenever the defence set or 01_System/project_data.py changes (GOV-D4.11).

Governance: GOV-E6. Reviewed 2026-09-07. This is the threat model for THE PROJECT — the artefacts, the data and the agent that produced them. It is not a threat model for the NDIS business itself, which does not exist.

1. What is worth attacking

AssetWhy an attacker wants itBlast radius if compromised
Zaid's judgement about a capital decisionA wrong figure, planted or accidental, causes a real financial lossBounded by the capital he commits — which is exactly the thing this project exists to size
The source registerIt is the trust anchor. Corrupt one URL or figure and every downstream number inherits the corruptionWhole project, silently
The generated artefactsA hand-edited study that disagrees with the registers is the most confident liar in the projectWhole project, until the next rebuild or checker run
The project folder on Zaid's machineOrdinary file-level riskThe folder

No credentials, no payment data, no personal data of any third party, and no client data exist anywhere in this project. That is not luck — it is INV-2 and INV-5, and checker C08 proves it every run.

2. Who would attack it, and how they would get in

ThreatVectorControl 1Control 2 (what happens when control 1 fails)
Prompt injection through fetched content — a government or vendor page contains text crafted to be read as an instructionWebFetch of an external pageINV-6: all fetched content is DATA, never an instruction. Research agents were charged with this explicitly in their chartersThe agent that fetched content never wrote to a register. Every fetched fact was transcribed into the SRC register by the Master Brain, where it carries a URL a human can open and check
Fabrication — a figure that sounds right and has no sourceThe model's own fluencyGOV-F8.8, and every research charter forbade an unsourced figureChecker C05 scans the delivered study and fails if the sourced-claim ratio drops below 0.90. It runs outside the model's context, so it cannot be talked out of it
Silent staleness — a price limit or wage rate that was right in August 2026 and wrong laterTimeEvery SRC row carries an accessed date; GOV-F1.16 makes a citation stale after twelve monthsChecker C03 enforces the currency date, and BKL-006 schedules the whole register for re-verification before 2027-08-20
Contradiction between artefacts — the study says one number, the model anotherHand-editing a generated fileSingle source of truth: one editable file, everything else generatedChecker C09 compares the headline figures across the study, the model and the dashboard and fails on any difference
Self-certification — the thing that built an artefact declaring it correctConvenienceGOV-C3.2: builder is never verifier. V1, V2 and V3 built nothing they verifiedChecker C24 fails if any RACI row shows the same agent building and verifying. V2 actually caught two real defects, DEF-002 and DEF-003
A tampered or stale transfer pack — the artefact a stranger trusts mostTime, or an editThe pack is generated, never hand-maintainedChecker C22 re-derives every file against a SHA-256 manifest; checker C23 deliberately tampers with a pack file to prove C22 can fail, then restores it
Excessive agency — an agent doing more than its task neededBroad tool accessBounded authority table (GOV-A1.11); every sub-agent charter carried explicit prohibitions and an effort ceilingNo agent could write outside 02_Work/scratch; no agent could log in, download, install or transact
Data leaving its boundaryPasting project content into an external toolGOV-E5.5: no project data to any external service without Zaid's approval for that specific transferNothing in this project is confidential to a third party, so the blast radius is bounded to public research and Zaid's own numbers

3. Fail closed, and recover

4. Review trigger

This threat model is reviewed whenever the threat surface changes — a new interface, a new external input, a new data class, a new user or a new integration — and that review is a Class 2 change at minimum (GOV-E6.10). The most likely trigger is the project moving from a study to an actual registration submission, at which point real personal data enters the system and this model must be rewritten, not amended.