Security policy, threat model, and audit documentation for the entire Matchids ecosystem. Phase 2 — this repo documents and coordinates security practice across all the phase 1 repos rather than containing runnable code itself.
SECURITY.md Responsible disclosure policy (org-wide)
docs/
THREAT_MODEL.md Assets, actors, threats and mitigations
SECURITY_ARCHITECTURE.md How security is actually implemented, by layer
VULNERABILITY_MANAGEMENT.md Intake process and severity guide
AUDIT_CHECKLIST.md Pre-launch checklist
Matchids serves children. Every threat entry in THREAT_MODEL.md that
touches child or family data is treated as high-impact by default, and
matchids-content's review workflow plus the absence of open social
features in phase 1 are architectural choices, not afterthoughts — see
matchids-docs/security/CHILD_SAFETY.md for the full reasoning.
Each product repo (matchids-backend, matchids-payments,
matchids-celoht, etc.) implements its own share of what's described
here and links back to this repo from its own README. This repo is where
the full picture — and the checklist to verify it before launch — lives
in one place.
See SECURITY.md.