Klugliv

Legal & Trust

Risk Register

Privacy, security, and trust risks we track and mitigate.

Risk Register (Privacy, Security & Trust)

Last updated: 2026-07-20

This register lists material risks Klugliv tracks for privacy, security, and trust. It is a living engineering document — not a certification or audit report.

Legend: Likelihood and impact are qualitative (Low / Medium / High). Status reflects the current repository and dev slice.

Active risks

IDRiskLikelihoodImpactMitigation / controlsStatus
R-01Receipt data breach (storage misconfiguration or credential leak)LowHighPrivate Supabase/S3 buckets; block public access; KMS for S3; no OCR keys in mobile; least-privilege IAMMitigated — monitor
R-02Unauthorized OCR/API abuse (cost or data processing without valid user session)MediumMediumSupabase JWT validation in Lambda; budgets/alarms; rate limiting roadmapPartial — JWT at Lambda, not API Gateway authorizer yet
R-03Cross-border OCR transfer (Google Vision processing location)MediumMediumDocument in vendor register; confirm transfer mechanisms with counselOpen — legal confirmation needed
R-04Analytics without clear consent (PostHog enabled per build)MediumMediumOpt-in prompt + Trust & privacy toggle; documented in privacy/cookie policiesMitigated — counsel to confirm jurisdiction fit
R-05Incorrect OCR affects user trust (wrong totals/items saved without review)MediumLowMandatory review screen before save; user can edit/delete receiptsMitigated by design
R-06Account deletion delay (no self-service delete yet)LowMediumSelf-service delete in Trust & privacy; email fallback documentedMitigated — monitor deletion failures
R-07Operational log PII exposure (receipt text in CloudWatch)LowMediumShort log retention; avoid DEBUG of full payloads in prodMitigated — discipline required
R-08Single-founder operational risk (incident response bandwidth)MediumMediumRunbooks in repo; incident-response doc; synthetic smoke scriptsAccepted — scale with team
R-09Third-party provider outage (Supabase, AWS, Vision)MediumMediumHybrid architecture; Edge OCR rollback flag documentedPartial — dual paths exist for OCR
R-10Impressum / legal entity incomplete (German market requirements)HighMediumPlaceholder Impressum with counsel-review bannerOpen — before DE production marketing
R-11Future voice features (privacy expectations if shipped without clear policy)LowHighNot implemented; hands-free design doc specifies no permanent audioPlanned — policy before launch
R-12Over-claiming compliance (ISO/SOC/GDPR “certified” marketing)LowHighExplicit “readiness review” language; no false certification claimsMitigated by documentation policy

Risk treatment process

  1. Identify — engineering changes, user reports, or playbook reviews surface new risks.
  2. Assess — update likelihood/impact and owner (currently engineering-led).
  3. Treat — mitigate, accept, transfer (vendor DPAs), or defer with documented gap.
  4. Review — update this register when architecture or legal scope changes.

Related documents

Updates

We publish meaningful changes here when risks are added, closed, or materially re-scored.

Contact: hello@klugliv.com

Klugliv — Adaptive household shopping intelligence