Skip to main content

Why Starfort exists

TODO — describe the three risk tiers (security, regulatory, quality) and how Starfort gives each to the right team.

The risk hierarchy

PriorityRisk typeExample threatsPosture
1AI securityPII leakage, confidential data exposure, jailbreak, prompt injectionCentrally enforced — non-negotiable
2AI regulatoryNational AI laws, domain regulation (finance, healthcare), internal policyCompliance required — central guidance + domain-specific application
3AI service qualityHallucination, UX degradationContinuous tuning — autonomous per service

Organizational model

TODO — describe Security team / AI Governance team / Service dev team roles (RACI matrix from PRD §2.3).

Next

Architecture overview

Skeleton, Core, and the data flow between them.