{"id":"security-permissiveness-spans-policy-and-data-boundaries","text":"Security permissiveness is systematic across two independent dimensions: policy enforcement (default-allow access control, trusted internal callers, no input validation) and data isolation (BCC recipients stored alongside visible recipients, presigned URL secrets shared across instances), creating a consistent availability-over-security bias that compounds — permissive policies let requests through, and weak data isolation lets those requests see more than intended.","truth_value":"OUT","source":"","source_url":"","source_hash":"","justifications":[{"type":"SL","antecedents":["data-isolation-gaps-parallel-access-control-gaps","default-to-permissive-across-security-dimensions"],"outlist":[],"label":"Access control gaps and data isolation gaps are parallel manifestations of the same permissive default"}],"dependents":[],"metadata":{"last_reviewed":"2026-06-05T18:21:49","review_result":"pass","_retracted":true},"created_at":"","updated_at":"2026-06-17T14:30:46+00:00","reviewed_at":"","verified_at":"","retracted_at":"2026-06-17T14:30:46+00:00","explanation":{"steps":[{"node":"security-permissiveness-spans-policy-and-data-boundaries","truth_value":"OUT","reason":"SL justification invalid","failed_antecedents":["default-to-permissive-across-security-dimensions"],"label":"Access control gaps and data isolation gaps are parallel manifestations of the same permissive default"}]}}