Surfaced by the 2026-08-13 student-data-inventory audit.
Two documents understate what is actually encrypted — both predate #518 / #520 / #521:
- the privacy policy's encryption enumeration
SECURITY.md §3.3
Since then, flashcards, study guides, room summaries, feedback/issue free text, and the quiz JSON payloads all became encrypted at rest. Under-claiming is the safe direction, but stale security docs are their own liability and they're now wrong in the reader's favour by enough to matter.
Also: ADR 0025 accepts but does not implement RAG chunk_text encryption. That gap should be either scheduled or explicitly re-accepted with a date, rather than left as an open acceptance with no expiry.
Surfaced by the 2026-08-13 student-data-inventory audit.
Two documents understate what is actually encrypted — both predate #518 / #520 / #521:
SECURITY.md§3.3Since then, flashcards, study guides, room summaries, feedback/issue free text, and the quiz JSON payloads all became encrypted at rest. Under-claiming is the safe direction, but stale security docs are their own liability and they're now wrong in the reader's favour by enough to matter.
Also: ADR 0025 accepts but does not implement RAG
chunk_textencryption. That gap should be either scheduled or explicitly re-accepted with a date, rather than left as an open acceptance with no expiry.