Security

Security documentation, audit reports, and remediation tracking for The Phenom App.

Security is foundational to The Phenom App’s mission of authenticated media verification. This section documents our security posture, audit findings, and remediation efforts.

This section contains security audit reports, vulnerability assessments, and active remediation trackers for Phenom infrastructure components. Access is restricted to the infrastructure and engineering team.

What is here

Page What it covers
Platform Security Assessment 2026-08 184 findings across 17 repositories, nine root causes, and the backlog that comes out of them
Drop Security Audit The earlier phenom-drop audit
Drop Remediation Tracker Remediation status against that audit

Platform Security Assessment 2026-08

Plain-language working notes on the August 2026 static security assessment of the Phenom estate: 184 findings, nine root causes, and a sequenced fix list ready to become GitHub epics and issues.

Security Remediation Planning

Plain-language guide to turning the verified security findings into GitHub epics and issues. What is actually broken, why it matters, what done looks like, and how to file it.

Drop Pipeline Security Audit

The March 2026 security audit of the Phenom Drop media pipeline, corrected on 2026-08-18 against the live code and live AWS state. Three of its claims did not survive verification.

Drop Remediation Tracker

Current security control state for the Phenom Drop pipeline. All findings active and deployed.