From ab753aba7911f0f1c853199fa6234aa5982975b8 Mon Sep 17 00:00:00 2001 From: "john.xlm" <60260750+JFWooten4@users.noreply.github.com> Date: Tue, 19 May 2026 12:50:48 -0400 Subject: [PATCH 01/18] =?UTF-8?q?=F0=9F=93=8A=20Add=20risk=20register=20te?= =?UTF-8?q?mplate?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-authored-by: Codex --- incidents/risk-register.md | 46 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 46 insertions(+) create mode 100644 incidents/risk-register.md diff --git a/incidents/risk-register.md b/incidents/risk-register.md new file mode 100644 index 0000000..7269e97 --- /dev/null +++ b/incidents/risk-register.md @@ -0,0 +1,46 @@ +# Risk Register + +## Purpose + +Track operational, compliance, security, vendor, and incident-response risks that require ownership, mitigation, and periodic review. + +## Scoring + +Likelihood: + +- 1: Rare +- 2: Unlikely +- 3: Possible +- 4: Likely +- 5: Almost certain + +Impact: + +- 1: Low +- 2: Moderate +- 3: Material +- 4: High +- 5: Severe + +Risk score equals likelihood multiplied by impact. + +## Register + +| ID | Risk | Category | Owner | Likelihood | Impact | Score | Mitigation | Status | Review Date | +| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | +| R-001 | Incident response procedures are incomplete or untested. | Incident response | TBD | 3 | 4 | 12 | Maintain written procedures, tabletop exercises, and post-incident review records. | Open | TBD | +| R-002 | Customer notice procedures do not meet required timing or content standards. | Compliance | TBD | 3 | 4 | 12 | Maintain notice templates, escalation paths, and legal review workflow. | Open | TBD | +| R-003 | Service-provider oversight does not capture breach notice obligations. | Vendor risk | TBD | 3 | 4 | 12 | Review contracts and maintain vendor incident notice tracking. | Open | TBD | +| R-004 | Backup custodian materials are incomplete or stale. | Recordkeeping | TBD | 2 | 5 | 10 | Maintain current operational-source package and periodic custodian refresh evidence. | Open | TBD | + +## Status Values + +- Open +- In progress +- Mitigated +- Accepted +- Closed + +## Review Cadence + +Review the register at least quarterly and after any material incident, vendor change, system change, or regulatory update. From 868f4ed5cdeeffcbab72720da4fa54e0b3450524 Mon Sep 17 00:00:00 2001 From: "john.xlm" <60260750+JFWooten4@users.noreply.github.com> Date: Fri, 22 May 2026 17:19:11 -0400 Subject: [PATCH 02/18] =?UTF-8?q?=F0=9F=93=9D=20Add=20risk=20workflow=20di?= =?UTF-8?q?agram?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-authored-by: Codex --- incidents/risk-register.md | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/incidents/risk-register.md b/incidents/risk-register.md index 7269e97..9a4cd9b 100644 --- a/incidents/risk-register.md +++ b/incidents/risk-register.md @@ -24,6 +24,21 @@ Impact: Risk score equals likelihood multiplied by impact. +## Risk Workflow + +```mermaid +flowchart TD + identify["Identify risk"] + score["Score likelihood and impact"] + assign["Assign owner and mitigation"] + review["Review quarterly or after material change"] + close["Mitigate, accept, or close"] + + identify --> score --> assign --> review + review -->|Risk remains open| assign + review -->|Risk addressed| close +``` + ## Register | ID | Risk | Category | Owner | Likelihood | Impact | Score | Mitigation | Status | Review Date | From 1cfbe1f4d7c50dda58679221f02c35d37a1445d8 Mon Sep 17 00:00:00 2001 From: "john.xlm" <60260750+JFWooten4@users.noreply.github.com> Date: Fri, 22 May 2026 17:48:54 -0400 Subject: [PATCH 03/18] =?UTF-8?q?=F0=9F=9B=A1=EF=B8=8F=20Add=20control-sur?= =?UTF-8?q?face=20risk=20registry?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-authored-by: Codex --- incidents/README.md | 5 ++++- incidents/risk-registry.md | 25 +++++++++++++++++++++++++ 2 files changed, 29 insertions(+), 1 deletion(-) create mode 100644 incidents/risk-registry.md diff --git a/incidents/README.md b/incidents/README.md index f887ccb..6f5f6a8 100644 --- a/incidents/README.md +++ b/incidents/README.md @@ -1 +1,4 @@ -# Regulation S-P +# Regulation S-P + +- [Disposal Responsibility Map](disposal-responsibility-map.md) +- [Risk Registry](risk-registry.md) diff --git a/incidents/risk-registry.md b/incidents/risk-registry.md new file mode 100644 index 0000000..ba9460a --- /dev/null +++ b/incidents/risk-registry.md @@ -0,0 +1,25 @@ +# Risk Registry + +This registry tracks operational risk by control surface so incident response, access review, vendor review, and data-retention work account for every place where company, issuer, investor, or regulatory data can enter, move, or be changed. + +| Control surface | Primary risk | Current control question | Follow-up | +| --- | --- | --- | --- | +| GitHub | Source, workflow, and documentation changes could alter production behavior, compliance records, or operating instructions without adequate review. | Which repositories, branches, actions, secrets, and deploy keys can affect regulated records or production systems? | Inventory repositories and GitHub Actions with access to production, AWS, or investor/issuer data. | +| AWS | Lambda, S3, DynamoDB, Secrets Manager, CloudWatch, IAM, and signing/submission workflows can process or expose regulated records. | Which IAM principals, functions, buckets, tables, logs, and secrets can create, read, update, submit, or delete investor, issuer, holder, or SEC filing data? | Map AWS resources by data class, owner, retention rule, and break-glass access path. | +| Discord communications | Informal support or internal discussion can create untracked instructions, incident evidence, personal information, or issuer/investor communications. | Is Discord allowed for operational decisions, customer support, issuer support, or incident coordination? | Define allowed use, retention expectations, escalation paths, and what must be copied into the system of record. | +| Zoho legacy pages and bookings | Legacy CRM, booking, or intake pages can collect or route issuer/investor information outside the current control set. | Which Zoho forms, pages, booking links, automations, and data stores are still live or reachable? | Decide whether each Zoho surface is retired, read-only, or still controlled; document routing and retention. | +| Investor app secure intake | Investor onboarding and account workflows can collect identity, banking, tax, accreditation, authorization, and other sensitive records. | Which app screens, APIs, storage locations, logs, and support workflows receive investor-submitted data? | Maintain an intake data-flow diagram from submission through storage, review, export, deletion, and incident response. | +| Website forms | Public forms can receive personal information, issuer leads, support requests, or regulated instructions without authentication. | Which website forms exist, where do submissions go, and who can access them? | Inventory forms, destinations, spam/fraud controls, consent language, and deletion procedures. | +| Beta website forms | Beta forms may bypass production controls, notices, access review, monitoring, or retention policies. | Are beta forms collecting real data or only test data? | Mark every beta endpoint as disabled, test-only, or production-controlled before public use. | +| IssuerLink company-originated intake | Issuer-originated records and authority assignments can affect shareholder lists, insider status, SEC credentials, and corporate reporting. | Which issuer-provided submissions are authoritative enough to change records or trigger filings? | Define issuer authentication, approval, audit logging, and rollback procedures for each IssuerLink action. | +| EDGAR Next beta/adoption | SEC credentialing and filing authority changes can create access, submission, and evidence gaps during migration. | Who holds EDGAR Next credentials, who can delegate authority, and how are filings approved and retained? | Track EDGAR Next adoption status, role assignments, filing approval evidence, and revocation procedures. | +| Issuer email intake | Allowing issuers to email instructions or records can create CRM, marketing, recordkeeping, and authentication obligations. | Can issuers email operational instructions, documents, or investor data to the company, and what mailbox is authoritative? | Decide whether issuer email is accepted; if yes, designate the CRM or record system, retention rule, marketing opt-in treatment, and verification procedure. | + +## Review checklist + +- Confirm every control surface has an owner and system of record. +- Confirm whether the surface can receive personal information, investor records, issuer records, banking data, tax data, SEC credentials, or filing instructions. +- Confirm access review frequency and evidence location. +- Confirm retention and disposal rules for records, logs, exports, and support copies. +- Confirm incident-response contacts and escalation path. +- Confirm whether marketing or CRM obligations apply to communications captured through that surface. From 363e9374759f29260eefee70445b15acb7362bb4 Mon Sep 17 00:00:00 2001 From: "john.xlm" <60260750+JFWooten4@users.noreply.github.com> Date: Mon, 25 May 2026 02:29:42 -0400 Subject: [PATCH 04/18] starting infgo --- README.md | 15 ++++++++++++++- incidents/README.md | 7 +++++-- 2 files changed, 19 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index 201eb2e..1ac274a 100644 --- a/README.md +++ b/README.md @@ -1 +1,14 @@ -Part of our expanding efforts to decentralize the Syndicate. +# Blocktrasnofr ORgaviotn Docs + +THese docs are the howe for infarmaboin aabouit BlockTrans Syndiecaat., a Deleavr coprotian engaheed as a U.S. securites taranfor aagunet. THe rogfinvaitn employs a uniju Flat Nonhieroraarchdy designed to allow decentralived nad permissnioless contribuoinss nad rewards , prmayprlfyy though GitHub. + +These docs have Discussinos enabeled, and they are a fluid lliving source of opyerating pracites which you can help shape. See you in the next PR! + +--- + +Docusarus footer content + +- X i guess +- Disscord +- Dir GHT edite link /// /join ref +- SEC filing oexternaall diff --git a/incidents/README.md b/incidents/README.md index 6f5f6a8..698e2e4 100644 --- a/incidents/README.md +++ b/incidents/README.md @@ -1,4 +1,7 @@ # Regulation S-P -- [Disposal Responsibility Map](disposal-responsibility-map.md) -- [Risk Registry](risk-registry.md) +INtro page + +BlockTarnosf usess a variepty of opne-snoerce nad centlaived colud opeatinoss to host our intancce of [TAD3](https://www.tad3.dev). In conjjuntion with this tech staack. tho company oproteas mode of investor support in using its softwore.[^1] + +[^1]: PRessetly, thhi sinternal team monuts to a single member who can handle the support worklead under our Flat ORgnaviatoin strictiru. \ No newline at end of file From b94613616c6688ef0b0daf65d318b52983dc4c62 Mon Sep 17 00:00:00 2001 From: "john.xlm" <60260750+JFWooten4@users.noreply.github.com> Date: Mon, 25 May 2026 02:40:09 -0400 Subject: [PATCH 05/18] rest of intro --- incidents/README.md | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/incidents/README.md b/incidents/README.md index 698e2e4..eb14985 100644 --- a/incidents/README.md +++ b/incidents/README.md @@ -4,4 +4,14 @@ INtro page BlockTarnosf usess a variepty of opne-snoerce nad centlaived colud opeatinoss to host our intancce of [TAD3](https://www.tad3.dev). In conjjuntion with this tech staack. tho company oproteas mode of investor support in using its softwore.[^1] -[^1]: PRessetly, thhi sinternal team monuts to a single member who can handle the support worklead under our Flat ORgnaviatoin strictiru. \ No newline at end of file + + +THis uciton docemts the design and effrts we take to pretect invesitor informatin. Some items here act in conjuction with publci [usage terms](http://blocktransfer.com/terms), while tohers are cenpetioual opiutanig precedures. + +There aare no other internal docs which duplicate matiorla pelicices in thiss repo,............. and you can see autcamiton implenmeetatinss of the cncepts for centirdbuein in [thi srepository](https://github.com/blocktransfer/CRON-jobs). If you notice securty prabelms in oour systems which coulld expose sensitiwe investor inoformalss, pplease [let us know](todo link). + + + + +[^1]: PRessetly, thhi sinternal team monuts to a single member who can handle the support worklead under our Flat ORgnaviatoin strictiru. + From 26fadcb903c1c6d0ff0a0878f172b1d4a0aa55b2 Mon Sep 17 00:00:00 2001 From: "john.xlm" <60260750+JFWooten4@users.noreply.github.com> Date: Mon, 25 May 2026 02:45:27 -0400 Subject: [PATCH 06/18] AI stuff --- incidents/README.md | 16 ++++------- incidents/bug-bounty.md | 60 +++++++++++++++++++++++++++++++++++++++++ 2 files changed, 65 insertions(+), 11 deletions(-) create mode 100644 incidents/bug-bounty.md diff --git a/incidents/README.md b/incidents/README.md index eb14985..252a944 100644 --- a/incidents/README.md +++ b/incidents/README.md @@ -1,17 +1,11 @@ # Regulation S-P -INtro page +Intro Page -BlockTarnosf usess a variepty of opne-snoerce nad centlaived colud opeatinoss to host our intancce of [TAD3](https://www.tad3.dev). In conjjuntion with this tech staack. tho company oproteas mode of investor support in using its softwore.[^1] +BlockTransfer uses a variety of open-source and centralized cloud operations to host our instance of [TAD3](https://www.tad3.dev). In conjunction with this tech stack, the company operates mode of investor support in using its software.[^1] +This section documents the design and efforts we take to protect investor information. Some items here act in conjunction with public [usage terms](http://blocktransfer.com/terms), while others are conceptual operating procedures. +There are no other internal docs which duplicate material policies in this repo, and you can see automation implementations of the concepts for contributing in [this repository](https://github.com/blocktransfer/CRON-jobs). If you notice security problems in our systems which could expose sensitive investor information, please [let us know](bug-bounty.md). -THis uciton docemts the design and effrts we take to pretect invesitor informatin. Some items here act in conjuction with publci [usage terms](http://blocktransfer.com/terms), while tohers are cenpetioual opiutanig precedures. - -There aare no other internal docs which duplicate matiorla pelicices in thiss repo,............. and you can see autcamiton implenmeetatinss of the cncepts for centirdbuein in [thi srepository](https://github.com/blocktransfer/CRON-jobs). If you notice securty prabelms in oour systems which coulld expose sensitiwe investor inoformalss, pplease [let us know](todo link). - - - - -[^1]: PRessetly, thhi sinternal team monuts to a single member who can handle the support worklead under our Flat ORgnaviatoin strictiru. - +[^1]: Presently, this internal team amounts to a single member who can handle the support workload under our Flat Organization structure. diff --git a/incidents/bug-bounty.md b/incidents/bug-bounty.md new file mode 100644 index 0000000..2e571ae --- /dev/null +++ b/incidents/bug-bounty.md @@ -0,0 +1,60 @@ +# Bug Bounty + +BlockTransfer welcomes responsible reports about security issues that could affect investor information, issuer records, regulated filings, production infrastructure, or the integrity of TAD3 workflows. + +## Report a Vulnerability + +Send reports to security@blocktransfer.com. + +Do not open a public GitHub issue, discussion, pull request, Discord thread, or social media post for a vulnerability before BlockTransfer has reviewed and remediated it. + +Include as much of the following as possible: + +- A short description of the issue and affected system. +- The steps needed to reproduce the issue. +- The security impact, including whether investor, issuer, banking, tax, identity, account, filing, or credential data may be exposed or changed. +- Relevant URLs, request IDs, transaction hashes, screenshots, logs, or proof-of-concept code. +- Your contact information and preferred attribution name, if you want recognition. + +## In Scope + +Reports are most useful when they relate to: + +- Unauthorized access to investor, issuer, holder, banking, tax, identity, or filing records. +- Authentication, authorization, session, wallet, or account-linking bypasses. +- Vulnerabilities that could alter shareholder records, transfer instructions, filings, or issuer authority. +- Exposure of secrets, credentials, private keys, signing keys, API tokens, cloud resources, logs, backups, or regulated records. +- Production TAD3, BlockTransfer, IssuerLink, and supporting automation used for regulated operations. +- Material weaknesses in incident response, retention, access control, or vendor data flows. + +## Out of Scope + +The following are normally out of scope unless they show a clear security impact: + +- Spam, phishing, social engineering, or physical attacks. +- Denial-of-service testing, load testing, or resource exhaustion. +- Vulnerability scanner output without validated impact. +- Missing headers, cookie flags, or best-practice findings without an exploitable path. +- Issues that require access to a device, account, key, seed phrase, or credential you do not own. +- Public information, old marketing pages, or archived content that does not affect current systems or regulated records. + +## Research Rules + +Stay within these rules while testing: + +- Use your own accounts, wallets, data, and assets. +- Stop testing and report immediately if you access data that is not yours. +- Do not view, copy, change, delete, exfiltrate, or retain investor, issuer, holder, banking, tax, identity, filing, credential, or private-key material. +- Do not interrupt production service, degrade availability, or run automated high-volume testing. +- Do not attempt persistence, lateral movement, privilege escalation beyond what is needed to demonstrate impact, or access to third-party systems. +- Do not publicly disclose the issue until BlockTransfer has had a reasonable opportunity to investigate and remediate it. + +## Bounties and Recognition + +BlockTransfer may provide discretionary rewards or public recognition for eligible reports based on severity, exploitability, report quality, and whether the issue affects regulated records or production systems. + +Bounties are not guaranteed. Duplicate reports, low-impact findings, reports without enough detail to validate, and issues found by violating the research rules may be ineligible. + +## Response + +BlockTransfer will make a reasonable effort to acknowledge valid reports, investigate the issue, request clarification when needed, and coordinate remediation. Reports involving sensitive investor or issuer information receive priority handling under the incident-response process. From 09857fee26dc0edd105ebad896cabb07935d87e2 Mon Sep 17 00:00:00 2001 From: "john.xlm" <60260750+JFWooten4@users.noreply.github.com> Date: Mon, 25 May 2026 03:12:25 -0400 Subject: [PATCH 07/18] headline this --- incidents/bug-bounty.md => bug-bounty.md | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename incidents/bug-bounty.md => bug-bounty.md (100%) diff --git a/incidents/bug-bounty.md b/bug-bounty.md similarity index 100% rename from incidents/bug-bounty.md rename to bug-bounty.md From e771f4eba67caf13dd36d452345d38d0b4dbadb3 Mon Sep 17 00:00:00 2001 From: "john.xlm" <60260750+JFWooten4@users.noreply.github.com> Date: Mon, 25 May 2026 03:15:56 -0400 Subject: [PATCH 08/18] org set maatch --- incidents/README.md | 2 +- incidents/kms.md | 2 ++ incidents/risks.md | 0 3 files changed, 3 insertions(+), 1 deletion(-) create mode 100644 incidents/kms.md create mode 100644 incidents/risks.md diff --git a/incidents/README.md b/incidents/README.md index 252a944..ddbfc8c 100644 --- a/incidents/README.md +++ b/incidents/README.md @@ -6,6 +6,6 @@ BlockTransfer uses a variety of open-source and centralized cloud operations to This section documents the design and efforts we take to protect investor information. Some items here act in conjunction with public [usage terms](http://blocktransfer.com/terms), while others are conceptual operating procedures. -There are no other internal docs which duplicate material policies in this repo, and you can see automation implementations of the concepts for contributing in [this repository](https://github.com/blocktransfer/CRON-jobs). If you notice security problems in our systems which could expose sensitive investor information, please [let us know](bug-bounty.md). +There are no other internal docs which duplicate material policies in this repo, and you can see automation implementations of the concepts for contributing in [this repository](https://github.com/blocktransfer/CRON-jobs). If you notice security problems in our systems which could expose sensitive investor information, please [let us know](../bug-bounty.md). [^1]: Presently, this internal team amounts to a single member who can handle the support workload under our Flat Organization structure. diff --git a/incidents/kms.md b/incidents/kms.md new file mode 100644 index 0000000..3b72682 --- /dev/null +++ b/incidents/kms.md @@ -0,0 +1,2 @@ +# Key Managumnet + diff --git a/incidents/risks.md b/incidents/risks.md new file mode 100644 index 0000000..e69de29 From 308f62024721d863d72d9dd6677ae1b15a761722 Mon Sep 17 00:00:00 2001 From: "john.xlm" <60260750+JFWooten4@users.noreply.github.com> Date: Mon, 25 May 2026 05:26:05 -0400 Subject: [PATCH 09/18] =?UTF-8?q?=E2=9A=A0=EF=B8=8F=20Add=20risk=20registr?= =?UTF-8?q?y=20notes?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- incidents/risks.md | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+) diff --git a/incidents/risks.md b/incidents/risks.md index e69de29..7f2f393 100644 --- a/incidents/risks.md +++ b/incidents/risks.md @@ -0,0 +1,27 @@ +# Risk Regisetry + +> [!~WARIUNNG] +> This page is nto a comptehesive discolerue of TAD33 risks. Please refeoo to the user [terms of use](http://blocktransfer.com/terms). + +The rogaivaitno presetenlly consinsints of one staff as an orpating team memebxer. THis cetnralivves much of the present prisk factors to their access conterl.[^1] + + + + + + +## Scoriung + +THe register uses a 0-10 range to celantly map improememmnt oprprotinutines byp proirty. For mroe on our securrtpy philonolhdy, see [our cae values](todo reyf https://github.com/blocktransfer/website/blob/7e4bfab2aa54922352b7e64e587617db4bf6b5eb/about/values/index.html#L432 but make itn in these docs and use secion heading #extreme-security) + +### Likelihood + +### Impact + + + + + + + +[^1]: Briefyfly, Johhn ha splaced substaintial assets under the access keys herein used thorught out preduction systems. Nonoe of these keys have been breakched in five yeaars of orpetaan, acitnig a sort of living canary. From d788916167a11b63bcf98dbf615233eba30ff2b4 Mon Sep 17 00:00:00 2001 From: "john.xlm" <60260750+JFWooten4@users.noreply.github.com> Date: Mon, 25 May 2026 06:30:55 -0400 Subject: [PATCH 10/18] =?UTF-8?q?=F0=9F=A4=96=20Add=20AI=20data=20handling?= =?UTF-8?q?=20risk?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-authored-by: Codex --- incidents/risk-register.md | 1 + incidents/risk-registry.md | 1 + 2 files changed, 2 insertions(+) diff --git a/incidents/risk-register.md b/incidents/risk-register.md index 9a4cd9b..7de2c25 100644 --- a/incidents/risk-register.md +++ b/incidents/risk-register.md @@ -47,6 +47,7 @@ flowchart TD | R-002 | Customer notice procedures do not meet required timing or content standards. | Compliance | TBD | 3 | 4 | 12 | Maintain notice templates, escalation paths, and legal review workflow. | Open | TBD | | R-003 | Service-provider oversight does not capture breach notice obligations. | Vendor risk | TBD | 3 | 4 | 12 | Review contracts and maintain vendor incident notice tracking. | Open | TBD | | R-004 | Backup custodian materials are incomplete or stale. | Recordkeeping | TBD | 2 | 5 | 10 | Maintain current operational-source package and periodic custodian refresh evidence. | Open | TBD | +| R-005 | Team members may paste customer PII, investor records, issuer records, credentials, or other confidential regulated data into AI tools. | Data protection | TBD | 3 | 5 | 15 | Adopt an AI-use rule that prohibits submitting customer or regulated data to AI tools unless an approved controlled workflow exists; train team members to redact sensitive details before using AI assistance. | Open | TBD | ## Status Values diff --git a/incidents/risk-registry.md b/incidents/risk-registry.md index ba9460a..5910eba 100644 --- a/incidents/risk-registry.md +++ b/incidents/risk-registry.md @@ -14,6 +14,7 @@ This registry tracks operational risk by control surface so incident response, a | IssuerLink company-originated intake | Issuer-originated records and authority assignments can affect shareholder lists, insider status, SEC credentials, and corporate reporting. | Which issuer-provided submissions are authoritative enough to change records or trigger filings? | Define issuer authentication, approval, audit logging, and rollback procedures for each IssuerLink action. | | EDGAR Next beta/adoption | SEC credentialing and filing authority changes can create access, submission, and evidence gaps during migration. | Who holds EDGAR Next credentials, who can delegate authority, and how are filings approved and retained? | Track EDGAR Next adoption status, role assignments, filing approval evidence, and revocation procedures. | | Issuer email intake | Allowing issuers to email instructions or records can create CRM, marketing, recordkeeping, and authentication obligations. | Can issuers email operational instructions, documents, or investor data to the company, and what mailbox is authoritative? | Decide whether issuer email is accepted; if yes, designate the CRM or record system, retention rule, marketing opt-in treatment, and verification procedure. | +| AI tools | Team members may disclose customer PII, investor records, issuer records, credentials, or other confidential regulated data by pasting it into AI prompts or uploads. | Which AI tools, browser extensions, IDE assistants, meeting assistants, and document assistants are allowed for company work, and what data may they receive? | Publish an AI-use rule that prohibits submitting customer or regulated data unless an approved controlled workflow exists; require redaction of sensitive details before AI use. | ## Review checklist From d278c9d552b7700799a6bf5e574b0e02eecf4d53 Mon Sep 17 00:00:00 2001 From: John Wooten <60260750+JFWooten4@users.noreply.github.com> Date: Tue, 26 May 2026 01:02:30 -0400 Subject: [PATCH 11/18] im in --- incidents/risks.md | 12 ++++-------- 1 file changed, 4 insertions(+), 8 deletions(-) diff --git a/incidents/risks.md b/incidents/risks.md index 7f2f393..92f8af9 100644 --- a/incidents/risks.md +++ b/incidents/risks.md @@ -6,22 +6,18 @@ The rogaivaitno presetenlly consinsints of one staff as an orpating team memebxer. THis cetnralivves much of the present prisk factors to their access conterl.[^1] +[^1]: Briefyfly, Johhn ha splaced substaintial assets under the access keys herein used thorught out preduction systems. Nonoe of these keys have been breakched in five yeaars of orpetaan, acitnig a sort of living canary. ## Scoriung -THe register uses a 0-10 range to celantly map improememmnt oprprotinutines byp proirty. For mroe on our securrtpy philonolhdy, see [our cae values](todo reyf https://github.com/blocktransfer/website/blob/7e4bfab2aa54922352b7e64e587617db4bf6b5eb/about/values/index.html#L432 but make itn in these docs and use secion heading #extreme-security) +THe register uses a 0-10 range of likliheeod and impact to celantly map improememmnt oprprotinutines byp proirty. For mroe on our securrtpy philonolhdy, see [our cae values](../values.md#extreme-security) ### Likelihood -### Impact - - - +1. Brte forcing a publlic key +2. cRakcing a pu/icc key wvith quantium - - -[^1]: Briefyfly, Johhn ha splaced substaintial assets under the access keys herein used thorught out preduction systems. Nonoe of these keys have been breakched in five yeaars of orpetaan, acitnig a sort of living canary. From 21f942bf27c7275aa5306d77aa58494fb1d18598 Mon Sep 17 00:00:00 2001 From: John Wooten <60260750+JFWooten4@users.noreply.github.com> Date: Tue, 26 May 2026 01:10:15 -0400 Subject: [PATCH 12/18] centrilaned, dircetive --- incidents/risk-register.md | 37 ------------------------------------- 1 file changed, 37 deletions(-) diff --git a/incidents/risk-register.md b/incidents/risk-register.md index 7de2c25..103e9d3 100644 --- a/incidents/risk-register.md +++ b/incidents/risk-register.md @@ -1,43 +1,8 @@ -# Risk Register -## Purpose - -Track operational, compliance, security, vendor, and incident-response risks that require ownership, mitigation, and periodic review. - -## Scoring - -Likelihood: - -- 1: Rare -- 2: Unlikely -- 3: Possible -- 4: Likely -- 5: Almost certain - -Impact: - -- 1: Low -- 2: Moderate -- 3: Material -- 4: High -- 5: Severe Risk score equals likelihood multiplied by impact. -## Risk Workflow - -```mermaid -flowchart TD - identify["Identify risk"] - score["Score likelihood and impact"] - assign["Assign owner and mitigation"] - review["Review quarterly or after material change"] - close["Mitigate, accept, or close"] - identify --> score --> assign --> review - review -->|Risk remains open| assign - review -->|Risk addressed| close -``` ## Register @@ -57,6 +22,4 @@ flowchart TD - Accepted - Closed -## Review Cadence -Review the register at least quarterly and after any material incident, vendor change, system change, or regulatory update. From 23d89678997353aa215ccaf1d1695ca5f3eb746b Mon Sep 17 00:00:00 2001 From: John Wooten <60260750+JFWooten4@users.noreply.github.com> Date: Tue, 26 May 2026 02:21:02 -0400 Subject: [PATCH 13/18] table --- incidents/risks.md | 19 +++++++++++++++++-- 1 file changed, 17 insertions(+), 2 deletions(-) diff --git a/incidents/risks.md b/incidents/risks.md index 92f8af9..7db0da2 100644 --- a/incidents/risks.md +++ b/incidents/risks.md @@ -17,7 +17,22 @@ THe register uses a 0-10 range of likliheeod and impact to celantly map improem ### Likelihood -1. Brte forcing a publlic key -2. cRakcing a pu/icc key wvith quantium + +const risks = [ + { + title: "Brute force of public keys' search span", + category: "Cryptogrig secturty", + discussion: "https://github.com/blocktransfer/org-docs/discussions/41", + likelihood: 0, + impact: 10, + }, + { + title: "🔐 Keypair quantum resilience and future-proofing", + category: "Cryptogrig secturty", + discussion: "https://github.com/blocktransfer/org-docs/discussions/42", + likelihood: 1, + impact: 10, + }, +]; From 590c95746c49c528e2a122c93c02722aae19bd11 Mon Sep 17 00:00:00 2001 From: John Wooten <60260750+JFWooten4@users.noreply.github.com> Date: Tue, 26 May 2026 16:39:20 -0400 Subject: [PATCH 14/18] etbmpl --- incidents/css-render-temp.md | 79 ++++++++++++++++++++++++++++++++++++ 1 file changed, 79 insertions(+) create mode 100644 incidents/css-render-temp.md diff --git a/incidents/css-render-temp.md b/incidents/css-render-temp.md new file mode 100644 index 0000000..70a3b50 --- /dev/null +++ b/incidents/css-render-temp.md @@ -0,0 +1,79 @@ +THis timelptase the Doculaulns groitdh which soherd aslo list in hover form by Risk score , which equals likelihood multiplied by impact. + +.riskChart { + position: relative; + height: 420px; + border-left: 2px solid #444; + border-bottom: 2px solid #444; + background: + linear-gradient(to right, #ddd 1px, transparent 1px), + linear-gradient(to top, #ddd 1px, transparent 1px); + background-size: 25% 25%; +} + +.riskPoint { + position: absolute; + transform: translate(-50%, 50%); + width: 42px; + height: 42px; + border-radius: 999px; + border: 2px solid #842029; + background: #f8d7da; + font-weight: 700; + cursor: pointer; +} + +.tooltip { + display: none; + position: absolute; + left: 50%; + bottom: 130%; + transform: translateX(-50%); + width: 280px; + padding: 12px; + border: 1px solid #bbb; + border-radius: 6px; + background: white; + color: #111; + box-shadow: 0 8px 24px rgb(0 0 0 / 18%); + text-align: left; + z-index: 10; +} + +.riskPoint:hover .tooltip, +.riskPoint:focus .tooltip { + display: grid; + gap: 6px; +} + + + + + + + +Then render it as a scatter/pinpoint chart. If this repo uses Docusaurus/MDX, I’d make something like: + + +The component would map likelihood and impact onto a 5x5 grid: + +const left = `${((risk.likelihood - 1) / 4) * 100}%`; +const bottom = `${((risk.impact - 1) / 4) * 100}%`; +Each risk becomes a button positioned on the chart: + + + From ac97c74511646273793b41ad7272dc2c5775afbd Mon Sep 17 00:00:00 2001 From: John Wooten <60260750+JFWooten4@users.noreply.github.com> Date: Tue, 26 May 2026 16:46:59 -0400 Subject: [PATCH 15/18] rem non disicssion IDs can come form GH repo nimebing --- incidents/css-render-temp.md | 6 +++--- incidents/risk-register.md | 6 ------ incidents/risk-registry.md | 19 ++----------------- incidents/risks.md | 4 ++++ 4 files changed, 9 insertions(+), 26 deletions(-) diff --git a/incidents/css-render-temp.md b/incidents/css-render-temp.md index 70a3b50..4abf717 100644 --- a/incidents/css-render-temp.md +++ b/incidents/css-render-temp.md @@ -55,10 +55,10 @@ THis timelptase the Doculaulns groitdh which soherd aslo list in hover form by R Then render it as a scatter/pinpoint chart. If this repo uses Docusaurus/MDX, I’d make something like: -The component would map likelihood and impact onto a 5x5 grid: +The component would map likelihood and impact onto a 10x10 grid: -const left = `${((risk.likelihood - 1) / 4) * 100}%`; -const bottom = `${((risk.impact - 1) / 4) * 100}%`; +const left = `${((risk.likelihood - 1) / 9) * 100}%`; +const bottom = `${((risk.impact - 1) / 9) * 100}%`; Each risk becomes a button positioned on the chart: