Security
The trust boundary, stated out loud.
An over-stated guarantee is a vulnerability. This is what ISNAD defends against, what it does not, and where the line is.
The operator is the root of trust
ISNAD grades what happens after the operator admits a narrator at the boundary. It cannot make a bad onboarding decision good; it can make the payoff of a bad decision small and the exposure of a caught narrator permanent.
The sleeper narrator
An identity that transmits faithfully for a long time, earns a high grade, then spends it once on one target.
Mitigated: per-domain grades, permanent integrity strikes (human-only), corroboration capped at HASAN (never SAHIH), version-drift reset.
Not mitigated (honest): a payload engineered to have no observable contradiction until it fires. Detection is retrospective; containment is prospective.
Reputation farming / Sybil
Many identities laundering one good grade, or one identity buying standing to be resold.
Mitigated: grades are local (no shared registry to poison), correlated chains are collapsed (SharedLineageDetector), corroboration requires genuinely independent narrators.
What ISNAD does not do
- · Verify that a source's metadata is authentic.
- · Fact-check a claim with no contradiction in your corpus.
- · Detect that a RELIABLE fake source plus a clean pipeline is still fake.
Attestations
None yet — no SOC 2, no pen test. We state this plainly rather than imply otherwise, and this page updates the moment that changes.
Published, versioned, and conservative — THREAT_MODEL.md ↗