Publish a what-we-do-not-protect-against page #97

Closed
opened 2026-09-23 10:46:09 +01:00 by cruelacid · 1 comment
Owner

Why

The single highest-credibility asset available to this product with this
audience, and most vendors will not publish one.
For a buyer who evaluates
security claims professionally, a published list of what a product does not
protect against is worth more than any amount of assurance.

The landing page already carries a short "What it does not claim" block. This is
the full version, and it has a gap in it that matters.

What to do

A page distilled from docs/security-model.md (the caveats at lines 102-140 and
226-276):

  • Not audited.
  • The server sees the membership graph — who shares which folder, and when.
  • Account and identity records, device records, sizes, timings and IPs are
    stored.
  • No forward secrecy for stored history.
  • No protection from a compromised device.
  • No isolation from other Obsidian plugins.
  • Android vaults share one secret store — signing one vault in signs them
    all in. Measured, not assumed.
  • No read-only membership, and the reason we cannot offer cheap read-only roles
    is the same reason we cannot read your notes.

The item that is not published anywhere yet

docs/launch-readiness.md Gate E records it in as many words:

"No published document claims the plugin sends nothing."

The client reports its own crashes to a self-hosted error tracker when signed in
to the hosted service. It is off in one click. This is exactly the kind of
thing a security audience finds by watching traffic and then never trusts you
again for not having said first.
Say it first, say where the reports go, and
say how to turn it off.

Constraints

  • Zero JavaScript, like every other page — the deploy enforces it.
  • Meta description 100–160 characters or page() throws.
  • Sentence case, no exclamation marks, success stated as fact.
  • This page's value is entirely in being complete. An omission found later costs
    more than the page ever earned.

Also record

A trigger for commissioning a real third-party audit, rather than leaving it
open-ended. Suggested: the first of 25 paying organisations or €15k ARR. A
protocol/crypto audit runs roughly €10k–40k, which is not spendable before any
customer conversation has happened.

## Why **The single highest-credibility asset available to this product with this audience, and most vendors will not publish one.** For a buyer who evaluates security claims professionally, a published list of what a product does *not* protect against is worth more than any amount of assurance. The landing page already carries a short "What it does not claim" block. This is the full version, and it has a gap in it that matters. ## What to do A page distilled from `docs/security-model.md` (the caveats at lines 102-140 and 226-276): - Not audited. - The server sees the membership graph — who shares which folder, and when. - Account and identity records, device records, sizes, timings and IPs are stored. - No forward secrecy for stored history. - No protection from a compromised device. - No isolation from other Obsidian plugins. - **Android vaults share one secret store** — signing one vault in signs them all in. Measured, not assumed. - No read-only membership, and the reason we cannot offer cheap read-only roles is the same reason we cannot read your notes. ### The item that is not published anywhere yet `docs/launch-readiness.md` Gate E records it in as many words: > "No published document claims the plugin sends nothing." The client reports its own crashes to a self-hosted error tracker when signed in to the hosted service. It is off in one click. **This is exactly the kind of thing a security audience finds by watching traffic and then never trusts you again for not having said first.** Say it first, say where the reports go, and say how to turn it off. ## Constraints - Zero JavaScript, like every other page — the deploy enforces it. - Meta description 100–160 characters or `page()` throws. - Sentence case, no exclamation marks, success stated as fact. - This page's value is entirely in being complete. An omission found later costs more than the page ever earned. ## Also record A trigger for commissioning a real third-party audit, rather than leaving it open-ended. Suggested: the first of 25 paying organisations or €15k ARR. A protocol/crypto audit runs roughly €10k–40k, which is not spendable before any customer conversation has happened.
cruelacid added this to the Marketing project 2026-09-23 10:48:13 +01:00
Author
Owner

Moved to the Vikunja board as NEC-73: https://projectron.nerchure.com/tasks/73

Moved to the Vikunja board as **NEC-73**: https://projectron.nerchure.com/tasks/73
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Nectenda/nectenda#97
No description provided.