Security Model & Threat Matrix
Architectural security guarantees, threat mitigations, and honest scope limitations for Opacus.
Threat Matrix
| Attack Vector | Prevented? | Mitigation Mechanism |
|---|---|---|
| Prompt Injection Attack | Yes | PCR condition mismatch & hard limit gatekeeper |
| Velocity / Infinite Loop Attack | Yes | Cumulative 24h spending rate limiter |
| Replay & Double Spend | Yes | Timestamped nonce idempotency validation |
| KMS Infrastructure Compromise | No | Outside technical scope |
Honest Scope Limitations
Opacus enforces financial transaction policy at the KMS boundary. It does not replace general LLM output moderation or prevent human social engineering attacks.