## Context A platform that ingests from CI and stores failure data is a target. Model the threats and close the gaps. ## Scope - [ ] Threat model (STRIDE) of ingestion, tokens, dashboard, AI path - [ ] Ingest-token rotation + scoping + leak detection - [ ] Secret scanning in CI + dependency audit (SCA) + SBOM - [ ] Rate-limit / abuse protection on public endpoints - [ ] Security policy + responsible disclosure ## Acceptance criteria - Documented threat model with mitigations tracked; automated dep + secret scanning in CI
Context
A platform that ingests from CI and stores failure data is a target. Model the threats and close the gaps.
Scope
Acceptance criteria