Purpose: Security architecture, threat model, AI guardrails, identity/access control, privacy, fairness, secure file handling, secrets management, incident response, and compliance checklist.
What belongs here: Security and governance policy documents, threat models, and review checklists. Legal/policy statements not yet confirmed are marked [LEGAL_REVIEW_REQUIRED].
What must not be stored here: Actual secrets, real incident details with PII, or vulnerability details that should go through the private process in SECURITY.md instead of a committed doc.
Owner: [TENANT_CONFIGURATION_REQUIRED — Security Architecture]
Main dependencies: .claude/rules/security.md, SECURITY.md, .github/workflows/security-scan.yml, config/defaults/security.default.yaml.
Contents: security-architecture.md · threat-model.md · ai-guardrails-policy.md · prompt-injection-defense.md · identity-access-control.md · privacy-and-pii-handling.md · fairness-and-bias-governance.md · secure-file-upload-policy.md · secrets-and-key-management.md · incident-response-runbook.md · security-test-plan.md · compliance-review-checklist.md · frontend-security.md
Status: Initial scaffold — details to be added during implementation.