Technical Paper

Security boundaries

1.7 Security boundaries

Yumo Yumo's security model separates which layer holds which data and which authority. The public document describes authority and data boundaries in an auditable way.

BoundaryHoldsAuthority separation
User deviceWallet signature, selected receipt file, local preprocessingUser signing stays device-side
Application servicesSession, upload orchestration, pipeline jobs, status eventsApplication services carry session and pipeline authority
Data planePseudonymous receipt records, derived observations, reward ledgerData plane carries record and ledger integrity
On-chain layerToken state, staking/treasury authorities, cryptographic commitmentsOn-chain layer carries token and commitment state
Operational control planeMonitoring, quotas, incident responseOperational control plane manages defense parameters

In this model, user data, reward accounting, and on-chain authority live in separate layers. Cross-boundary transitions happen through typed events and auditable records; signing procedures, emergency playbooks, and threshold values are managed in private operational documentation.