{"id":51863469,"url":"https://github.com/fevra-dev/subrosa","last_synced_at":"2026-07-24T12:01:12.822Z","repository":{"id":371952588,"uuid":"1289995025","full_name":"fevra-dev/Subrosa","owner":"fevra-dev","description":"Privacy engineering suite — nine Claude Code skills plus a citation-backed regulatory taxonomy across 26 jurisdictions, bridged by a statutory dissolution map. Compliance is a floor; selective disclosure is the ceiling.","archived":false,"fork":false,"pushed_at":"2026-07-17T22:14:01.000Z","size":15271,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-07-18T00:15:11.769Z","etag":null,"topics":["ccpa","claude-code","claude-skills","compliance","cryptography","cypherpunk","data-minimization","data-protection","dpia","gdpr","hipaa","opsec","privacy","privacy-by-design","privacy-engineering","redaction","regulatory-compliance","threat-modeling","zero-knowledge"],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/fevra-dev.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-07-05T13:05:34.000Z","updated_at":"2026-07-17T22:14:42.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/fevra-dev/Subrosa","commit_stats":null,"previous_names":["fevra-dev/subrosa"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/fevra-dev/Subrosa","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fevra-dev%2FSubrosa","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fevra-dev%2FSubrosa/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fevra-dev%2FSubrosa/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fevra-dev%2FSubrosa/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/fevra-dev","download_url":"https://codeload.github.com/fevra-dev/Subrosa/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fevra-dev%2FSubrosa/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35841138,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-07-20T02:08:10.276Z","status":"online","status_checked_at":"2026-07-24T02:00:07.870Z","response_time":62,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["ccpa","claude-code","claude-skills","compliance","cryptography","cypherpunk","data-minimization","data-protection","dpia","gdpr","hipaa","opsec","privacy","privacy-by-design","privacy-engineering","redaction","regulatory-compliance","threat-modeling","zero-knowledge"],"created_at":"2026-07-24T12:01:11.809Z","updated_at":"2026-07-24T12:01:12.817Z","avatar_url":"https://github.com/fevra-dev.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cp align=\"center\"\u003e\n  \u003cimg src=\"assets/subrosa-logo.png\" alt=\"Subrosa — a geometric rose, hanging from its stem\" width=\"300\"\u003e\n\u003c/p\u003e\n\n# Subrosa\n\n*Sub rosa — \"under the rose.\" The rose hung over a Roman council table meant: what is said here stays here. Confidentiality by mutual understanding; selective disclosure by architecture.*\n\nSubrosa is a privacy engineering suite that takes both halves of the privacy problem seriously: the **cypherpunk half** (privacy must be structural — built from cryptographic primitives that make over-disclosure impossible) and the **regulatory half** (statute-precise compliance mapping across 27 jurisdictional and sectoral records). Its thesis, enforced rather than asserted:\n\n\u003e **Compliance is a floor. Selective disclosure is the ceiling.**\n\n## What's here\n\n```\nskills/                          Nine Claude Code skills (SKILL.md + references/)\n  privacy-suite/                 Router — diagnoses the need, sequences the others\n  threat-model-privacy/          IC-methodology adversary profiling (7 archetypes)\n  data-minimization/             Field-level schema audits, P1–P7, remediation vocabulary\n  consent-language/              Notices, cookie consent, rights pages, breach letters\n  privacy-impact-assessment/     DPIA/PIA workflow, regulator-ready output\n  opsec-review/                  Inferential-leakage audit before anything ships\n  redact/                        PII/credential/wallet scrubbing (regex + crypto patterns)\n  metadata-hygiene/              EXIF/document/AV/archive/git metadata stripping\n  privacy-architecture/          The build layer: ZKP, anonymous credentials, blind\n                                 signatures, commitments, stealth addresses, PSI/MPC,\n                                 DP, TEE, mixnets — with the Statutory Dissolution Map\ntaxonomy/                        The normalized regulatory layer\n  regulatory-taxonomy.md         Frozen axis set (A0–A12) + sectoral profile (S0–S5)\n  regulatory-taxonomy--*.md      27 jurisdiction/sectoral records, citation-backed\n  --floor.md                     Strictest-regime-wins: build to this, comply everywhere\n  --conflicts.md                 C1–C8: where regimes collide (incl. AML vs anonymity)\n  --arch-rollup.md               Which obligations dissolve under selective disclosure\n.fable/                          Methodology provenance: lessons, reconciliation log,\n                                 dogfood tests, phase prompts\n```\n\n## The two-layer design\n\n**The taxonomy layer** normalizes every regime — GDPR/UK, PIPEDA + Quebec Law 25, CCPA/CPRA, LGPD, POPIA, PIPL, the PDPA family, APPI, DPDPA, the APPs, nFADP, KR PIPA, and sectoral overlays (HIPAA, GLBA, COPPA, BIPA, FERPA, ePrivacy, NIS2, DORA, EU AI Act) — onto one frozen axis set. Every cell carries a statutory citation or an explicit `[UNVERIFIED]` flag, plus an enforcement-mode tag: **ARCH-DISSOLVES** (the duty never attaches to a well-designed system), **ARCH-SATISFIES** (a technical measure discharges it), **PROCEDURAL** (only paper satisfies it), or **ARCH-MANDATES** (the law demands the architecture itself — AU APP 2's anonymity option, BIPA § 15(c)'s profit ban, India's child-tracking prohibition).\n\n**The architecture layer** builds what the tags promise. Its Statutory Dissolution Map (`skills/privacy-architecture/references/regulatory-dissolution.md`) runs the bridge in the other direction: pick a primitive, read off exactly which obligations it dissolves, with record citations — so an ADR's compliance claim is auditable, not vibes. Roll-up finding: **~60% of tagged obligations across all records dissolve or discharge architecturally; the procedural remainder is five workflows of paper.**\n\n## Methodology (why this is trustworthy)\n\nEvery statutory claim was either traced to a grounding source or flagged — never guessed. The discipline caught real errors that a hand-authored reference had carried confidently: a folkloric \"72-hour\" Quebec breach clock (the statute says *promptly*), a section-shifted POPIA condition table, a duplicated LGPD rights anchor, a conflated Swiss provision, an uncorroborated UAE penalty figure — and one entire superseded statute (Vietnam's Decree 13 → PDPL 91/2025). All corrections are logged with sources in `.fable/reconciliation-log.md`; a Currency Protocol (quarterly sweeps, supersession banners) keeps the records from rotting. The repo enforces its own invariants in CI: `tools/validate.py` verifies every cross-reference resolves, every skill's frontmatter is well-formed, and every record carries a current `Current as of` date — and prints the `[UNVERIFIED]` census so flag-debt is visible per commit.\n\n## The canonical texts\n\nSubrosa's design principle — privacy must be structural, not procedural — has a fifty-year lineage. The suite quotes and builds on all of it:\n\n| Text | Author | Year | Core contribution |\n|---|---|---|---|\n| \"New Directions in Cryptography\" | Diffie \u0026 Hellman | 1976 | Public key cryptography — made everything possible |\n| \"Untraceable Electronic Mail, Return Addresses, and Digital Pseudonyms\" | David Chaum | 1981 | Mix networks — metadata unlinkability; ancestor of every mixnet |\n| \"Blind Signatures for Untraceable Payments\" | David Chaum | 1982 | Anonymous digital cash — first working implementation |\n| \"Security without Identification\" | David Chaum | 1985 | Full philosophical and technical statement of privacy-by-architecture |\n| \"The Knowledge Complexity of Interactive Proof Systems\" | Goldwasser, Micali \u0026 Rackoff | 1985 | Zero-knowledge formalized — proof without disclosure |\n| \"The Crypto Anarchist Manifesto\" | Timothy C. May | 1988 | Political framework; crypto anarchy program |\n| \"Why I Wrote PGP\" | Philip Zimmermann | 1991 | Cryptography as civil disobedience |\n| \"A Cypherpunk's Manifesto\" | Eric Hughes | 1993 | Privacy as selective disclosure; transaction necessity |\n| \"The Cyphernomicon\" | Timothy C. May | 1994 | 370-page FAQ; comprehensive philosophical reference |\n| \"A Declaration of the Independence of Cyberspace\" | John Perry Barlow | 1996 | Maximalist position; architecture over law |\n| \"b-money\" | Wei Dai | 1998 | Anonymous distributed electronic cash |\n| \"Code and Other Laws of Cyberspace\" | Lawrence Lessig | 1999 | Code is law; architectural regulation |\n| \"Trusted Third Parties are Security Holes\" | Nick Szabo | 2001 | Architectural principle for trust minimization |\n| \"Bitcoin: A Peer-to-Peer Electronic Cash System\" | Satoshi Nakamoto | 2008 | Implementation of the cypherpunk program |\n\nFull text-by-text mapping — each canonical work tied to the cryptographic primitive it authorizes and its place in the suite — is `skills/privacy-architecture/references/lineage.md`. Narrative exposition: `skills/privacy-suite/SKILL.md` §The Intellectual Lineage. Per-primitive epigraphs anchor each architecture reference (Chaum 1982 → blind signatures; GMR 1985 / May 1988 → ZKPs; Nakamoto 2008 §10 → Web3 privacy; Szabo 2001 → the TEE-as-minimized-TTP framing; Diffie–Hellman 1976 → everything).\n\n## Using the skills\n\nEach `skills/\u003cname\u003e/SKILL.md` is a Claude Code skill (frontmatter `name`/`description`, references loaded on demand). Install by copying into `~/.claude/skills/` or registering the repo as a plugin; start with `privacy-suite`, which routes to the rest.\n\n---\n\n**Not legal advice.** The taxonomy is an engineering reference for schema design, disclosure drafting, and architecture decisions. Verify effective dates and pending rulemakings against primary sources before advising in a regulated context — the Currency Protocol tells you how stale any record is.\n\n*Hughes, 1993: \"Cypherpunks write code.\" This repo is that code, with citations.*\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffevra-dev%2Fsubrosa","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ffevra-dev%2Fsubrosa","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffevra-dev%2Fsubrosa/lists"}