Document Classification: Internal — CHLOM Confidential Owner: CrownThrive, LLC Last Updated: 2025-08-08
1 — Architecture & Governance
- System Architecture Spec (SAS) — Compliance Engine + ZKP Verifier
- Data Architecture & Governance (DAG) + API Gateway & Feature Store Specs
- Security & Threat Model (STM) + TLaaS Contract Spec + ZKP Circuit Book
- SRE Playbook + Trade‑Secret Handling SOP + Proprietary Algorithm Doc Skeleton
- Risk & Bias Assessment (RBA) + CaaS API Spec (OpenAPI)
- TLaaS Contract API & Governance Addendum + ZKP Circuit Performance/Audit Appendix
- Model Card Template + Testing Strategy
2 — Usage & Navigation
2.1 Document Access
All referenced docs are stored in secure, access‑controlled repositories under the CHLOM internal doc namespace. Each has a canonical name as listed above.
2.2 Versioning
- Phase 0→1 master index maintained with semantic versioning.
- Updates to individual docs increment patch number; structural index changes increment minor.
2.3 Linking Conventions
- Use document title as primary link text.
- Append date stamp in
3 — Maintenance & Review
- Quarterly Review: Architecture, governance, and API specs.
- Monthly Review: Security, threat model, SLAs.
- Continuous Review: Testing strategy, bias assessment upon model retrain.
- Change Control: All updates require sign‑off by Lead Architect + Security Lead + Compliance Officer.
4 — Developer Guidance
- Always start with the System Architecture Spec before diving into any component build.
- For data work, consult the DAG doc before touching Feature Store or pipelines.
- Security considerations are non‑optional — review STM before implementing changes.
- All code touching ZKP or TLaaS must adhere to the Circuit Book and Contract Spec.
- Reliability and operational excellence require following the SRE Playbook.
- New models must ship with a Model Card and pass all gates in the Testing Strategy.
5 — Phase 1 Readiness Checklist (Derived from Phase 0→1 Docs)
- CE + ZKV deployed with all SLAs met in staging.
- Data lineage and retention enforced per DAG.
- Threat model mitigations tested in live fire/chaos tests.
- TLaaS contract deployed with governance hooks live.
- All ZKP circuits audited and benchmarked.
- Bias detection and drift monitoring live.
- 100% passing status in Testing Strategy gates.
End of Master Index — All referenced documents must be maintained in sync with this index for audit readiness.