When authority is stale, contradictory, unsupported, or overbroad, the safer default is hold, deny, expire, or aggregate rather than expand access.
LAKANA Sovereign Systems · review surface
Threat Model
A reviewer-facing map of difficult conditions, expected LAKANA responses, remaining limitations, and validation still needed before stronger public claims are justified.
Threats named explicitlyFail-closed where possibleOver-release riskUnder-release riskMetadata riskValidation gap visible
Adversarial surface
Threats are named instead of hidden.
Review rule: LAKANA does not claim that local-first design removes risk. It changes the default posture: narrower release, explicit denial, stale-state expiry, custody logging, and validation requirements before deployment claims.
| Threat | Severity | Affected subsystem | Expected response | Remaining limitation | Validation needed |
|---|---|---|---|---|---|
| Device compromise or tamper | High | CivOS, NICOLE, TSARO | Contract authority, isolate local state, refuse broad release, log denial where possible. | Physical control of a device remains difficult to govern. | Device integrity, tamper, secure storage, and persistence tests. |
| Sensor spoofing or replay | High | W-X, SSI, SOS, TSARO | Freshness gates, contradiction detection, stale-state denial, fail-closed when unsupported. | Public site does not prove production anti-spoofing. | Bench replay, drift, saturation, dropout, and correlated spoof tests. |
| Stale environmental truth | Medium | W-X / WX-Ag | Authority decay, stale denial, fallback to conservative support state. | Field consequences of stale data need calibration. | Clock drift, sensor outage, Mesonet/radar mismatch, and TTL experiments. |
| Timestamp manipulation | High | CivOS, NICOLE, W-X, SOS | Reject replay-like sequences, log stale/non-release, narrow responder scope. | Time integrity depends on hardware and protocol design. | Monotonic counter, clock skew, delayed packet, and replay-window tests. |
| Metadata leakage | High | NICOLE, BFB/TAB | Minimize event content; separate live communication from retained evidence; expire sessions. | Session timing and access patterns can still reveal sensitive context. | Metadata minimization audit, privacy threat model, and retention review. |
| Overbroad responder request | High | BFB/TAB, NICOLE, SOS | Typed request, declared purpose, announcement, bounded session, closure, denial logging. | Governance cannot assume every external actor requests only what is needed. | Responder workflow review, legal review, misuse testing, and access review. |
| Pressure to share too much | High | NICOLE, BFB/TAB, user governance | Scope separation, event audit, non-release as explicit state. | Human pressure is not solved by software alone. | Safety, legal, vulnerable-user, guardian, and consent-flow review. |
| Low battery or connectivity loss | Medium | CivOS, SOS | Degraded mode, transport fallback, authority narrowing, stale expiry. | Under-release risk if thresholds are too conservative. | Degraded-device, low-power, accessibility, and rural connectivity testing. |
| Over-release | High | TSARO, NICOLE, BFB/TAB | Minimize release, require typed scope, deny broad stream, log boundary. | Bad thresholds could release too much in ambiguous contexts. | Privacy red-team, scenario-based access review, false escalation analysis. |
| Under-release or false fail-closed | High | SOS, CivOS, TSARO | Fail-closed protects privacy but can delay help if too conservative. | Safety tradeoff requires external protocol design. | Human factors, emergency simulation, false negative, and escalation-ladder testing. |
| Location leakage | High | SOS, BFB/TAB, NICOLE | Release minimized location only under scoped rescue; avoid continuous tracking by default. | Even minimal location can be sensitive. | Geofence precision, corridor release, fuzzing, retention, and access-log review. |
| Audit-log misuse | Medium | NICOLE | Log grants, denials, expiry, handoff, and non-release with minimized content. | Audit logs themselves can become surveillance artifacts. | Retention policy, encryption review, role-based access, deletion and disclosure testing. |
| Employer or coach surveillance creep | High | SSI, NICOLE, Integrated Engine | Aggregate-only by default unless rescue or bounded medical/role scope applies. | Institutional incentives can pressure users into broad release. | Worker-rights review, athlete governance review, aggregate threshold tests. |
| Clinical overinterpretation | High | SSI | Non-diagnostic language; burden and retained time are modeled outputs. | Users may read structural burden as injury diagnosis. | Sports medicine, IRB, clinical validation, and return-to-play boundary review. |
| Official-weather substitution | Medium | W-X / WX-Ag | State not official weather authority; complement/validate local truth state. | Users may mistake public demo for forecast authority. | Weather authority disclaimers, partner review, Mesonet/radar comparison protocols. |
| Agronomic prescription overclaim | Medium | WX-Ag | Yield and anoxia are modeled endpoints; no crop guarantee. | Farm decisions could be affected by overconfident wording. | Extension review, crop-specific calibration, field plots, and agronomic validation. |
| Dataset provenance or license mismatch | High | All research stacks | Evidence-tier gate, manifest, source inventory, and support status flags. | Public pages must not imply restricted data can be commercialized. | Dataset license audit, provenance manifest, commercial-safe/research-licensed separation. |
| Simulation-to-real gap | High | Global LAKANA | Evidence posture labels simulations as internal/model-bound unless externally validated. | Strong simulation can still fail in messy deployment. | Bench tests, prototype pilots, partner-supervised field trials, external validation. |
Threat posture summary
The core defense is not “trust us.” It is narrower authority.
Denials, stale states, fallback, expiry, and non-release are first-class events so reviewers can inspect restraint rather than just positive releases.
Production claims require hardware red-team tests, privacy review, responder workflow validation, clinical review where relevant, and field protocols.