Privacy is enforced through architecture, not policy statements. Here is where the evidence for that lives - and where it's still incomplete.
An honest trust center names its own gaps. These are not yet available and are not represented anywhere on this site as complete. The table below turns that gap list into a public assurance roadmap - what's needed, who's expected to own it, and where the evidence will land once it exists.
| Assurance item | Status | Owner | Target | Evidence |
|---|---|---|---|---|
| System threat model | In progress | Security Council | Not yet published | Draft |
| Privacy threat model | Planned | LIFE Foundation | Not yet published | Scope |
| OpenID conformance | In progress | ClearSoftware | Not yet published | Test results |
| Independent penetration test | Scheduled | Independent assessor | Not yet published | Engagement |
| Data-flow diagrams | In progress | Architecture team | Not yet published | Draft diagrams |
| Retention schedule | In review | Providers | Not yet published | Policy |
| Provider compatibility suite | Planned | LIFE Foundation | Not yet published | Repository |