UNSIGNED PREVIEW — not a promoted public release.

Threat Model

Ireland

This page is generated from default_threat_model() and separates mitigated risks from non-goals.

In-Scope Threats

government_blocking

Government or network actors could block the primary website, search UI, or release pages.

Mitigation: Publish signed releases with mirror, offline-package, Git, and local-sharing fallbacks so the data can be verified away from the primary site.

data_tampering

Stored evidence, promises, ratings, or generated site files could be silently altered.

Mitigation: SHA-256 content hashes, signed release manifests, append-only corrections, transparency-log entries, and local verification checks expose tampering.

malicious_forks

A fork or mirror could change ratings, remove sources, or modify methodology while presenting itself as the original release.

Mitigation: Show signed-release trust badges, verification links, checksum guidance, and a browser-local fork diff viewer for release and public API artifacts.

partisan_capture

Contributors or reviewers could bias evidence selection, suppress counter-evidence, or promote partisan interpretations.

Mitigation: Multi-reviewer thresholds, dissent preservation, conflict tracking, correction history, and public methodology make interpretation reviewable.

source_disappearance

Public sources can disappear, move behind paywalls, or be edited after a promise rating has been published.

Mitigation: Require source content hashes, archived-copy paths when available, retrieval timestamps, and release checksums that preserve what was cited.

ai_error

AI-assisted extraction or drafting could hallucinate promises, omit context, or overstate fulfillment.

Mitigation: Machine drafts are not publishable ratings; evidence, counter-evidence, rationale, reviewer thresholds, and correction records remain required before publication.

Explicit Non-Goals

legal_pressure

Legal threats or takedown pressure could chill publication, corrections, or reviewer participation.

Mitigation: Keep evidence separate from interpretation, publish methodology and corrections, and preserve signed release history; xeroes is not legal advice or legal protection.

user_risk

Readers, reviewers, or would-be sources could infer that xeroes provides anonymity, safety guarantees, or legal protection.

Mitigation: Public pages state that active intake is public-source-only; SecureDrop, OnionShare, and other anonymous channels are deferred until operator and security review.