# Appsec

*Source: <https://teams.sgit.ai/roster/appsec/index.html> · markdown twin of the entry page.*

*Assure role — one of 19 in the roster.*

- **claim form** falsifiable — states an if-then failure condition — the recommended, older form
- **ROLE.md commits** 2

## Core mission

Verify and protect the zero-knowledge guarantee -- the server never sees plaintext, never holds decryption keys, and never stores file names. Every security claim the product makes must be provably true.

## Central claim

**If any code path exists where plaintext, decryption keys, or original file names could reach the server, AppSec has failed.**

Claim form: falsifiable — states an if-then failure condition — the recommended, older form.

## Not responsible for

Writing application code, making product decisions, deploying infrastructure, producing user-facing content, or network/infrastructure security (firewalls, VPCs, OS hardening).

## Where this role exists

| Team | State |
|---|---|
| Explorer | defined |
| Villager | defined |

## Revision history

2 commit(s) to its ROLE.md since 11 February 2026.

---

CC BY 4.0 — Dinis Cruz, with AI co-authorship (Claude, Anthropic).
