Root docs
Repository viewer
Legacy docs parity surface
Back to repository viewer
Repository document

Risk Register

risk-register.md

Boundary

This route preserves legacy markdown access inside the Next.js surface. The raw repository file remains authoritative.

Open raw file

Risk Register

Purpose

This register summarizes the most important real risks that remain relevant to PrivateDAO after the current hardening and documentation work.

The intent is to make residual risk explicit rather than implicit.

RiskCategoryCurrent StatusMitigation SurfaceResidual Note
mainnet release without external auditdeployment / assuranceopenreadiness docs, audit handoff, release gatesno external audit is claimed by the repository
production signer misuse or poor custodyoperationsopenproduction operations, cutover runbook, incident responserequires real organizational controls outside the codebase
RPC degradation or divergenceinfrastructureopenmonitoring docs, RPC health scripts, operator checkliststill depends on provider selection and active monitoring
strategy alpha / APY proof not embedded in protocol packageproduct / competition fitopenRanger docs, strategy operations, risk policyrequires the paired strategy stack and live or backtest evidence
Android runtime verification outside this shellproduct surfacepartialAndroid native docs and codefull runtime validation needs Android SDK/device environment
commit-reveal hides vote content but not timing metadataprivacy boundaryknown design limitprotocol docs and threat modelthis is documented honestly and not treated as solved privacy
CustomCPI is intentionally unsupported rather than arbitrary CPI executionexecution scopeintentionalprotocol spec, tests, and docsunsupported actions are rejected to keep the live execution surface conservative

Use

Review this register before:

  • audit handoff
  • mainnet cutover
  • grant or competition submission
  • production operations planning