Edu-Carone-SA puts Atlas through a production-readiness reality check
Before adapting Mike for internal use, this fork maps the risks that could matter most to legal teams handling sensitive work.
Rather than rushing into a build, Eduardo Carone assembled a due-diligence baseline: software inventories, security scans, an architecture plan, a threat model, and licensing decisions. The proposed direction uses managed cloud services, private encrypted storage, and a web firewall, while deferring bigger platform changes.
The review identified several production blockers:
- Tenant data lacks the access controls needed to contain a credential leak.
- Raw AI exchanges may be written to disk.
- One case-opinions route is accessible without sign-in.
- The AGPL licence position needs legal approval before external access.
It also flags weak sharing controls, non-expiring download links, limited audit trails, and upload-processing risks. This was a closed, unmerged proposal, so it is a useful warning map rather than a delivered deployment.
Spotted something wrong? Or know the PR text has fresher detail than the writeup above?