The AONE Handbook
Security & assurance
Threat modelling, audit trails and the evidence an institutional assessor asks for.
Threat modelling a public-sector systemHow we model abuse of a credential-issuing system before writing code — trust boundaries, the abuse cases that actually occur, and what each one costs to stop.11 min readAudit trails that survive an auditAppend-only design, hash chaining, what must never be logged, and how to prove to an assessor that the record in front of them is complete.9 min read