**To unblock the compliance track today: send the architecture diagram now, escalate the stalled dependency-list request straight to Okafor, and get written answers on pentest scope and Lisbon working before they stall further.** **Already settled — no action needed:** - A security review is mandatory before production; whether a penetration test is also required is decided *during* that review. - Aldergate's internal hardening framework exists but doesn't substitute for the review. - Working...
$npx -y skills add welltraum/minto --skill raw --agent claude-code
Installs into .claude/skills of the current project.
Are you the author of Raw?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/welltraum-raw-b4facd10)
**To unblock the compliance track today: send the architecture diagram now, escalate the stalled dependency-list request straight to Okafor, and get written answers on pentest scope and Lisbon working before they stall further.**
**Already settled — no action needed:**
- A security review is mandatory before production; whether a penetration test is also required is decided *during* that review.
- Aldergate's internal hardening framework exists but doesn't substitute for the review.
- Working from Ireland is approved.
**Still open — three things to do today, in order of leverage:**
1. **Send the draft architecture diagram now.** It's the one blocker fully in our hands — ready since 11 Aug, sitting unsent — and it's what Aldergate needs to answer data storage, encryption and logging (gate review Q7). Nothing else on the compliance track moves until this goes.
2. **Escalate the approved-package list directly to Okafor, not through Whitcombe.** Promised 12 May by Mercer, re-promised 9 July by Whitcombe, still not delivered — 98 days open. Whitcombe has been relaying, not deciding; Okafor is the actual information security owner and has never joined a call. Go to Okafor directly with a hard date.
3. **Force written answers on two items nobody has committed to:**
- Whether critical dependencies need individual sign-off, and what the real turnaround is (currently "case by case" — this is what's letting the package-list slip).
- Whether the two Lisbon-based engineers are acceptable — raised 9 July, met with silence from Aldergate since.
**Bottom line:** build-phase pricing (risk R-07) stays open until items 2 and 3 close, and item 1 is the one lever we control outright — it should go out before the next sync.