Edu-Carone-SA puts legal and security gates ahead of production

This fork starts with a clear message: no commercial rollout until its licensing and security risks are understood and closed.

compliancesecurity

Edu-Carone-SA has laid down the governance scaffolding before making product claims. The fork now documents its current and intended architecture, hosting and data-storage choices, security threats, and the decisions behind them.

Most notably, it treats AGPL compliance as a production blocker, reflecting the obligations attached to the upstream project's licence. It also records software component inventories, giving reviewers a clearer view of the dependencies that would sit beneath a deployed legal-AI service.

The work is organised around sprint checkpoints, making the fork's hardening roadmap easier to follow on GitHub.

So what Managing partners, GCs and legal-tech founders should care if they need evidence that a prospective platform is taking deployment risk and open-source obligations seriously.

View this fork on GitHub →

Spotted something wrong? Or know the PR text has fresher detail than the writeup above?

Commits in this thread

1 commit from Edu-Carone-SA/mike, oldest first. Source extracted verbatim from the harvested git log.

SHA Subject Author Date
18dc17e8 docs(foundation): Sprint 0 baseline, architecture, threat model, ADRs, SBOMs and upstream analysis EduardoCarone 2026-07-10 ↗ GitHub
Sprint 0 conclusion: READY to start Sprint 1. Production NO-GO until P0 risks are closed.

Capture this thread into my fork

Download a single Markdown prompt that tells Claude how to port every commit above into your working tree — adapting paths and structure to match your repo. Run it via claude -p < capture-thread-966.md from inside the repo you want the changes in.

⬇ Download capture-thread-966.md