**The compliance track is blocked on two things you control, and you can clear both today: send the draft architecture diagram, and get a direct line to S. Okafor.** Security requirements have been open since 3 May and the build price can't be fixed without them (risk register R-07), but the two items still missing from Aldergate aren't waiting on Aldergate's goodwill — one is waiting on a diagram that has sat in draft since 11 August, and the other has been promised twice by someone who isn'...
Scanned 9/19/2026
Install to Claude Code
npx -y skills add welltraum/minto --skill raw --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Raw?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/welltraum-raw-c2c50f66)More formats (shields.io, HTML) on the badges page.
**The compliance track is blocked on two things you control, and you can clear both today: send the draft architecture diagram, and get a direct line to S. Okafor.** Security requirements have been open since 3 May and the build price can't be fixed without them (risk register R-07), but the two items still missing from Aldergate aren't waiting on Aldergate's goodwill — one is waiting on a diagram that has sat in draft since 11 August, and the other has been promised twice by someone who isn't the owner.
**What's already answered — treat as settled, don't re-ask.** A security review before production is mandatory, and whether a penetration test is added is decided by the assigned reviewer during the review, not in advance (gate review Q1). An internal hardening framework exists to build against, but conformance does not waive the review (Q2). Dependency usage — including critical dependencies — is assessed inside that same review rather than approved package by package (Q4), and there is no standard turnaround time to plan against; it's case by case (Q5). Work from Ireland is acceptable (Q6).
**What you still need, and why it's stuck.** The approved-package list was promised by D. Mercer on 12 May and again by R. Whitcombe on 9 July, both times with no date; it is 98 days open (R-11). Storage, encryption and logging requirements were explicitly declined until Aldergate sees an architecture diagram and gets a design walkthrough (Q7) — Fernway agreed on 9 July to send the diagram before the next sync and has not (R-14). Both threads run through Whitcombe, who relays; S. Okafor, named on 9 July as the information security owner, has never attended a joint meeting.
**One thing nobody has answered, and it isn't in the register.** Aldergate approved Ireland only (Q6). Fernway's PM mentioned two engineers in Lisbon at the 9 July sync and no one from Aldergate responded. That silence is not approval, and it is not tracked as a risk — if those two engineers are staffed on this build, it can surface during the mandatory review, after the price is fixed.
**Today:** send the draft diagram to Whitcombe with a request for the design walkthrough slot, ask in writing for a dated commitment on the package list, ask for Okafor directly on both, and raise Lisbon explicitly rather than letting the silence stand.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!