Roadmap item 9/10 · Workstream: Security · Risk: High · Approval required: Yes · Target milestone: M2 — Governed intake
Objective
Turn each finding from the Gemini red-team exercise into a tracked, testable control with an owner, so findings become verified mitigations rather than a static report.
Non-goals
- Re-running the red-team exercise
- Publishing exploit detail — this repository is public
Acceptance criteria
Dependencies
Risk
High — unresolved findings are known, documented attack paths.
Test evidence required
- For each mitigated finding: a regression test or a reproducible verification step showing the attack no longer works
- Register export showing no untriaged findings
Definition of done
Objective
Turn each finding from the Gemini red-team exercise into a tracked, testable control with an owner, so findings become verified mitigations rather than a static report.
Non-goals
Acceptance criteria
Dependencies
Risk
High — unresolved findings are known, documented attack paths.
Test evidence required
Definition of done