Reference — generated from the toolkit
Source of truth: toolkit/registers/security-exceptions.md. Edit it there; this page is regenerated on build.
Security exception & risk-acceptance register
Every gate waiver and accepted security risk in one place — so "fast" never quietly becomes "insecure". Reviewed monthly.
Schema
| Field | Notes |
|---|---|
| ID | SE-NNNN |
| Gate / control waived | which check |
| Product | affected product |
| Reason | why the exception |
| Compensating controls | what mitigates it meanwhile |
| Owner | named |
| Expiry | hard date — the gate re-blocks after |
| Status | active / expired / closed |
Rules
- Every waiver from the merge gate, security gates or STOP exit gate lands here.
- Security-critical findings are not waivable — they never appear here; they're fixed.
- Reviewed monthly by the toolkit governance group; expired exceptions re-block automatically.
- Backed by signed risk-acceptance records.