Skip to content

Risk Register

Top company risks

ID Risk Likelihood Impact Source Mitigation status
R-1 Auth-layer vulnerabilities block safe re-architecture work Medium High Infrastructure — re-architecture work (service boundaries, multi-region auth) is materially riskier against an unverified auth layer In progressfix/auth-bypass-and-shimmy-image branch active; MySQL test connectivity, deleted_at migration, and auth test assertions outstanding before merge
R-2 Single-global-CAC modelling error in international expansion Medium High Pillar I — explicitly flagged as the single most common early-stage international-expansion modelling error Mitigated by design — Pillar I's model already builds in a Tier 1 vs. Tier 2/3 CAC multiplier; risk is in execution discipline, not methodology
R-3 UK Online Safety Act "duty of care" category threshold triggers stricter compliance requirements at scale Medium Medium–High Pillar I — flagged as needing formal legal assessment before scale triggers stricter thresholds Not started — needs a formal legal assessment commissioned, not left implicit
R-4 SQLite audit-logging cannot support multi-region rollout volume High (if unaddressed before Tier 2 rollout) Medium Infrastructure — explicitly flagged as a near-term, not distant, risk Planned — recommended migration to Aurora before, not during, first Tier 2 market rollout
R-5 Synthetic/AI-generated spam and coordinated inauthentic behaviour outpaces volume-based moderation heuristics High (structural, worsens over time) High Shimmy Shield — Horizon 3's "80%-synthetic-content world" Planned — shift to behavioural-economic signals (cross-session identity consistency, proof-of-personhood, cost-to-post models) sequenced into Horizon 3
R-6 Regulatory audit-log requirements (UK OSA, EU DSA) retrofitted late, at high cost Low (if acted on now) / High (if deferred) High Shimmy Shield — "regulatory alignment as embedded infrastructure, not compliance overhead" Planned — compliance logging designed to be built into the ML pipeline from day one, not retrofitted
R-7 AI coding agent output overstates verification (e.g. claims tests pass when they don't) Medium Medium Operational pattern observed directly in current engineering workflow (GPT-5.3-Codex output cross-checked against Claude) Ongoing mitigation — active practice of cross-checking AI agent output rather than trusting verification claims at face value
R-8 Pillar IV (Building & Growth) is incomplete beyond the current hiring roadmap High (blocks accurate milestone dating) Medium Pillar IV Not started
R-9 Fundraising readiness gaps — no cap table, no confirmed SEIS/EIS split, no governance structure documented High (blocks credible external fundraising) High The Ask & Team Not started
R-10 CAC/penetration assumptions presented as point estimates rather than sensitivity bands, undermining investor credibility Low (if discipline holds) Medium Pillar I — explicitly flagged as a credibility risk for board/investor-facing projections Mitigated by design — Financials document inherits the low/base/high band requirement; risk is in execution discipline

Risk heatmap plotting all ten company risks by likelihood and impact, with R-5 (synthetic spam) and R-9 (fundraising readiness) sitting in the high-likelihood, high-impact zone

Review cadence

This register should be reviewed on the same cadence as the Roadmap & Milestones document — recommended quarterly, with each risk re-rated and any newly closed mitigations moved to a "resolved" log rather than deleted, so the suite retains a record of what was addressed and when.