Threat modeling
Document assets, actors, trust boundaries, abuse cases, and mitigations as architecture matures.
Trust / Security
Novera treats security as a lifecycle discipline across requirements, design, implementation, testing, and release. Current safeguards and planned controls are intentionally separated.
The public repository defines reporting scope and handling guidance. No external audit or certification is claimed.
Open SECURITY.mdControl posture
Document assets, actors, trust boundaries, abuse cases, and mitigations as architecture matures.
The MVP is limited to synthetic data and should not accept real identity documents or sensitive customer information.
Credentials, keys, seed phrases, and production configuration remain outside public materials and source.
Security review is a production eligibility requirement. No completed audit is claimed.
Operational monitoring, incident response, and continuity controls will be defined before production eligibility.
The public repository includes scope, reporting guidance, and a non-public contact path.
Do not submit real identity documents, customer data, payment credentials, wallet keys, confidential legal documents, or regulated records to the MVP or through the public contact flow.
No smart-contract, application, infrastructure, compliance, or certification audit is represented as complete. Any future audit will be named, dated, scoped, and linked.
Report a vulnerability
Please follow the reporting guidance in the public repository. Do not include sensitive personal data or exploit public systems while reporting.
Security reporting instructionsSystem trust
Security posture depends on the architecture, product scope, integration status, and regulatory boundaries working together.