Edu-Carone-SA puts Atlas through a production-readiness reality check

Before customising Mike for Atlas, this fork has drawn a firm line between local experimentation and safe production use.

securityinfrastructure

Edu-Carone-SA has completed the unglamorous but necessary first pass: mapping the system, its dependencies and its data flows, then recording what would have to change before real legal work could run on it. The result includes a software inventory, a threat model and a deployment plan built around managed cloud services and private encrypted storage.

More importantly, the review found four stop signs for production: tenant records lack proper row-level access controls; raw AI exchanges may be written to disk; one case-opinions route is open without sign-in; and the team still needs legal clarity on the licence before external access. It also flags gaps around sharing permissions, expiring download links, audit trails, upload limits and known third-party vulnerabilities.

Local development can begin, but production is explicitly held back until those issues clear.

So what Legal teams considering a hosted or client-facing Mike deployment should care because this is the governance and security work that separates a promising fork from a system ready to hold sensitive matters.

View this fork on GitHub →

Spotted something wrong? Or know the PR text has fresher detail than the writeup above?

Commits in this thread

1 commit from Edu-Carone-SA/mike, oldest first. Source extracted verbatim from the harvested git log.

SHA Subject Author Date
18dc17e8 docs(foundation): Sprint 0 baseline, architecture, threat model, ADRs, SBOMs and upstream analysis EduardoCarone 2026-07-10 ↗ GitHub
Sprint 0 conclusion: READY to start Sprint 1. Production NO-GO until P0 risks are closed.

Capture this thread into my fork

Download a single Markdown prompt that tells Claude how to port every commit above into your working tree — adapting paths and structure to match your repo. Run it via claude -p < capture-thread-1220.md from inside the repo you want the changes in.

⬇ Download capture-thread-1220.md