{
  "assetsProtected": [
    "personal and financial data before AI sharing",
    "authentication and recovery secrets",
    "AI account identity and sessions",
    "connected email, files, contacts, browser, and payment authority",
    "money and durable-data actions"
  ],
  "claimBoundary": "CapitalGuard Personal AI Safety 0.1 identifies supported scam, link, sensitive-data, identity, account, connector, and AI-action risk signals in exact user-supplied inputs using local deterministic checks. It can reduce avoidable exposure and prompt independent verification. It does not provide antivirus, network firewall, VPN, credit monitoring, insurance, identity restoration, dark-web monitoring, sender authentication, voice or video authenticity detection, or a guarantee that content is safe or fraudulent; it cannot control actions outside a CapitalGuard-controlled workflow.",
  "failClosedConditions": [
    "invalid or expired policy",
    "authority mismatch",
    "fingerprint-key mismatch",
    "malformed or oversized input",
    "unsafe object key",
    "URL-count overflow",
    "invalid signed report or action policy"
  ],
  "inScopeThreats": [
    "urgent payment and impersonation pressure",
    "credential and recovery-code solicitation",
    "remote-access requests",
    "risky or official-domain-mismatched URLs",
    "supported personal or financial data pasted into AI",
    "weak AI-account authentication or recovery hygiene",
    "overbroad connectors",
    "AI payment or destructive action authority",
    "evidence tamper"
  ],
  "outOfScopeThreats": [
    "malware and device compromise",
    "unseen messages or data",
    "voice or video deepfake classification",
    "sender authentication",
    "arbitrary multilingual semantics",
    "all possible PII formats",
    "dark-web, credit, bank, or identity monitoring",
    "actions outside a CapitalGuard-controlled workflow",
    "host or authority-key compromise"
  ],
  "schemaVersion": "cg-personal-ai-safety-threat-model-0.1.0",
  "version": "0.1.0"
}
