llms.sgit.ai / documents / security

The Security Model, And The Gap In It

Where the key lives, the two key tiers and why the difference is cryptographic rather than a policy check, the four-layer ladder of grant, consent, budget and policy, the argument that the recording indicator is trustworthy because the app cannot draw it, and the CSP egress gap stated plainly with the instruction not to soften it.

Document
03__the-security-model.md
Kind
Security brief
Length
about 1.1k words
Pack
llms.sgit.ai brief pack v0.33.62, 24 August 2026
Licence
CC BY 4.0, Dinis Cruz, with AI co-authorship
Raw
briefs/03__the-security-model.md is the source of truth

What it produced on this site

The document, in full

Rendered from the raw file below. The raw markdown is the source of truth: this page is presentation, and nothing here is edited.

Open the raw markdown