Edu-Carone-SA puts Atlas through a production-readiness reality check

Before customising Mike for Atlas, this fork has drawn a firm line between local experimentation and safe production use.

securityinfrastructure

Edu-Carone-SA has completed the unglamorous but necessary first pass: mapping the system, its dependencies and its data flows, then recording what would have to change before real legal work could run on it. The result includes a software inventory, a threat model and a deployment plan built around managed cloud services and private encrypted storage.

More importantly, the review found four stop signs for production: tenant records lack proper row-level access controls; raw AI exchanges may be written to disk; one case-opinions route is open without sign-in; and the team still needs legal clarity on the licence before external access. It also flags gaps around sharing permissions, expiring download links, audit trails, upload limits and known third-party vulnerabilities.

Local development can begin, but production is explicitly held back until those issues clear.

So what Legal teams considering a hosted or client-facing Mike deployment should care because this is the governance and security work that separates a promising fork from a system ready to hold sensitive matters.

View this fork on GitHub →

Spotted something wrong? Or know the PR text has fresher detail than the writeup above?