LAKANA Sovereign Systems · review surface

Threat Model

A reviewer-facing map of difficult conditions, expected LAKANA responses, remaining limitations, and validation still needed before stronger public claims are justified.

Threats named explicitlyFail-closed where possibleOver-release riskUnder-release riskMetadata riskValidation gap visible

Adversarial surface

Threats are named instead of hidden.

Review rule: LAKANA does not claim that local-first design removes risk. It changes the default posture: narrower release, explicit denial, stale-state expiry, custody logging, and validation requirements before deployment claims.
ThreatSeverityAffected subsystemExpected responseRemaining limitationValidation needed
Device compromise or tamperHighCivOS, NICOLE, TSAROContract authority, isolate local state, refuse broad release, log denial where possible.Physical control of a device remains difficult to govern.Device integrity, tamper, secure storage, and persistence tests.
Sensor spoofing or replayHighW-X, SSI, SOS, TSAROFreshness gates, contradiction detection, stale-state denial, fail-closed when unsupported.Public site does not prove production anti-spoofing.Bench replay, drift, saturation, dropout, and correlated spoof tests.
Stale environmental truthMediumW-X / WX-AgAuthority decay, stale denial, fallback to conservative support state.Field consequences of stale data need calibration.Clock drift, sensor outage, Mesonet/radar mismatch, and TTL experiments.
Timestamp manipulationHighCivOS, NICOLE, W-X, SOSReject replay-like sequences, log stale/non-release, narrow responder scope.Time integrity depends on hardware and protocol design.Monotonic counter, clock skew, delayed packet, and replay-window tests.
Metadata leakageHighNICOLE, BFB/TABMinimize event content; separate live communication from retained evidence; expire sessions.Session timing and access patterns can still reveal sensitive context.Metadata minimization audit, privacy threat model, and retention review.
Overbroad responder requestHighBFB/TAB, NICOLE, SOSTyped request, declared purpose, announcement, bounded session, closure, denial logging.Governance cannot assume every external actor requests only what is needed.Responder workflow review, legal review, misuse testing, and access review.
Pressure to share too muchHighNICOLE, BFB/TAB, user governanceScope separation, event audit, non-release as explicit state.Human pressure is not solved by software alone.Safety, legal, vulnerable-user, guardian, and consent-flow review.
Low battery or connectivity lossMediumCivOS, SOSDegraded mode, transport fallback, authority narrowing, stale expiry.Under-release risk if thresholds are too conservative.Degraded-device, low-power, accessibility, and rural connectivity testing.
Over-releaseHighTSARO, NICOLE, BFB/TABMinimize release, require typed scope, deny broad stream, log boundary.Bad thresholds could release too much in ambiguous contexts.Privacy red-team, scenario-based access review, false escalation analysis.
Under-release or false fail-closedHighSOS, CivOS, TSAROFail-closed protects privacy but can delay help if too conservative.Safety tradeoff requires external protocol design.Human factors, emergency simulation, false negative, and escalation-ladder testing.
Location leakageHighSOS, BFB/TAB, NICOLERelease minimized location only under scoped rescue; avoid continuous tracking by default.Even minimal location can be sensitive.Geofence precision, corridor release, fuzzing, retention, and access-log review.
Audit-log misuseMediumNICOLELog grants, denials, expiry, handoff, and non-release with minimized content.Audit logs themselves can become surveillance artifacts.Retention policy, encryption review, role-based access, deletion and disclosure testing.
Employer or coach surveillance creepHighSSI, NICOLE, Integrated EngineAggregate-only by default unless rescue or bounded medical/role scope applies.Institutional incentives can pressure users into broad release.Worker-rights review, athlete governance review, aggregate threshold tests.
Clinical overinterpretationHighSSINon-diagnostic language; burden and retained time are modeled outputs.Users may read structural burden as injury diagnosis.Sports medicine, IRB, clinical validation, and return-to-play boundary review.
Official-weather substitutionMediumW-X / WX-AgState not official weather authority; complement/validate local truth state.Users may mistake public demo for forecast authority.Weather authority disclaimers, partner review, Mesonet/radar comparison protocols.
Agronomic prescription overclaimMediumWX-AgYield and anoxia are modeled endpoints; no crop guarantee.Farm decisions could be affected by overconfident wording.Extension review, crop-specific calibration, field plots, and agronomic validation.
Dataset provenance or license mismatchHighAll research stacksEvidence-tier gate, manifest, source inventory, and support status flags.Public pages must not imply restricted data can be commercialized.Dataset license audit, provenance manifest, commercial-safe/research-licensed separation.
Simulation-to-real gapHighGlobal LAKANAEvidence posture labels simulations as internal/model-bound unless externally validated.Strong simulation can still fail in messy deployment.Bench tests, prototype pilots, partner-supervised field trials, external validation.

Threat posture summary

The core defense is not “trust us.” It is narrower authority.

Default non-release

When authority is stale, contradictory, unsupported, or overbroad, the safer default is hold, deny, expire, or aggregate rather than expand access.

Visible failures

Denials, stale states, fallback, expiry, and non-release are first-class events so reviewers can inspect restraint rather than just positive releases.

Validation remains necessary

Production claims require hardware red-team tests, privacy review, responder workflow validation, clinical review where relevant, and field protocols.