Skip to main content

Security Exceptions

Exceptions must be explicit, owned, time-bound, approved, and backed by a compensating control. Permanent exceptions are not allowed.

Exception IDStatusControl / GateOwnerExpiresApprovalCompensating ControlEvidence
EXC-001openSICARIO-MISSING-THREAT-MODEL — threat-model section required on every featureMaintainers2027-01-01TBDExternal threat-modeling process documented in project wiki; verify still enforces abuse-cases and data-classificationgenerated/sicario/gate-summary.json
EXC-002openSICARIO-MISSING-DIAGRAMS — system-context diagram requiredMaintainers2026-09-01TBDArchitecture decision records (ADRs) capture the same structural information in prosegenerated/sicario/gate-summary.json