Legal & Trust
Risk Register
Privacy, security, and trust risks we track and mitigate.
Risk Register (Privacy, Security & Trust)
Last updated: 2026-07-20
This register lists material risks Klugliv tracks for privacy, security, and trust. It is a living engineering document — not a certification or audit report.
Legend: Likelihood and impact are qualitative (Low / Medium / High). Status reflects the current repository and dev slice.
Active risks
| ID | Risk | Likelihood | Impact | Mitigation / controls | Status |
|---|---|---|---|---|---|
| R-01 | Receipt data breach (storage misconfiguration or credential leak) | Low | High | Private Supabase/S3 buckets; block public access; KMS for S3; no OCR keys in mobile; least-privilege IAM | Mitigated — monitor |
| R-02 | Unauthorized OCR/API abuse (cost or data processing without valid user session) | Medium | Medium | Supabase JWT validation in Lambda; budgets/alarms; rate limiting roadmap | Partial — JWT at Lambda, not API Gateway authorizer yet |
| R-03 | Cross-border OCR transfer (Google Vision processing location) | Medium | Medium | Document in vendor register; confirm transfer mechanisms with counsel | Open — legal confirmation needed |
| R-04 | Analytics without clear consent (PostHog enabled per build) | Medium | Medium | Opt-in prompt + Trust & privacy toggle; documented in privacy/cookie policies | Mitigated — counsel to confirm jurisdiction fit |
| R-05 | Incorrect OCR affects user trust (wrong totals/items saved without review) | Medium | Low | Mandatory review screen before save; user can edit/delete receipts | Mitigated by design |
| R-06 | Account deletion delay (no self-service delete yet) | Low | Medium | Self-service delete in Trust & privacy; email fallback documented | Mitigated — monitor deletion failures |
| R-07 | Operational log PII exposure (receipt text in CloudWatch) | Low | Medium | Short log retention; avoid DEBUG of full payloads in prod | Mitigated — discipline required |
| R-08 | Single-founder operational risk (incident response bandwidth) | Medium | Medium | Runbooks in repo; incident-response doc; synthetic smoke scripts | Accepted — scale with team |
| R-09 | Third-party provider outage (Supabase, AWS, Vision) | Medium | Medium | Hybrid architecture; Edge OCR rollback flag documented | Partial — dual paths exist for OCR |
| R-10 | Impressum / legal entity incomplete (German market requirements) | High | Medium | Placeholder Impressum with counsel-review banner | Open — before DE production marketing |
| R-11 | Future voice features (privacy expectations if shipped without clear policy) | Low | High | Not implemented; hands-free design doc specifies no permanent audio | Planned — policy before launch |
| R-12 | Over-claiming compliance (ISO/SOC/GDPR “certified” marketing) | Low | High | Explicit “readiness review” language; no false certification claims | Mitigated by documentation policy |
Risk treatment process
- Identify — engineering changes, user reports, or playbook reviews surface new risks.
- Assess — update likelihood/impact and owner (currently engineering-led).
- Treat — mitigate, accept, transfer (vendor DPAs), or defer with documented gap.
- Review — update this register when architecture or legal scope changes.
Related documents
- GDPR Compliance Review — structured gap analysis
- Launch Compliance Checklist — pre-release gates
- Incident Response
- Security Whitepaper
Updates
We publish meaningful changes here when risks are added, closed, or materially re-scored.
Contact: hello@klugliv.com