Skip to content

Security

The trust boundary, stated out loud.

An over-stated guarantee is a vulnerability. This is what ISNAD defends against, what it does not, and where the line is.

The operator is the root of trust

ISNAD grades what happens after the operator admits a narrator at the boundary. It cannot make a bad onboarding decision good; it can make the payoff of a bad decision small and the exposure of a caught narrator permanent.

The sleeper narrator

An identity that transmits faithfully for a long time, earns a high grade, then spends it once on one target.

Mitigated: per-domain grades, permanent integrity strikes (human-only), corroboration capped at HASAN (never SAHIH), version-drift reset.

Not mitigated (honest): a payload engineered to have no observable contradiction until it fires. Detection is retrospective; containment is prospective.

Reputation farming / Sybil

Many identities laundering one good grade, or one identity buying standing to be resold.

Mitigated: grades are local (no shared registry to poison), correlated chains are collapsed (SharedLineageDetector), corroboration requires genuinely independent narrators.

What ISNAD does not do

  • · Verify that a source's metadata is authentic.
  • · Fact-check a claim with no contradiction in your corpus.
  • · Detect that a RELIABLE fake source plus a clean pipeline is still fake.

Attestations

None yet — no SOC 2, no pen test. We state this plainly rather than imply otherwise, and this page updates the moment that changes.

Read the full threat model →

Published, versioned, and conservative — THREAT_MODEL.md ↗