Banana Navy
Catalog FR
Lab · Threat modeling IA · Fiche détaillée

Repudiation and weak evidence

the user (or the system) denies what was said or done because the evidence is not robust (tampered logs, missing evidence).

SheetF8
CategoryR-TB7-01 (repudiation)
Layers18 · Audit Logging
Systemvoicebot IA

tamper-evident logging (immutable, encrypted logs, verifiable timestamps), compliant retention, the ability to reconstruct a disputed decision.

The threat

the user (or the system) denies what was said or done because the evidence is not robust (tampered logs, missing evidence).

Angle mortWhy classic frameworks miss it

repudiation is reduced to a logs box with no non-malleability requirement: an editable log proves nothing.

MitigationProposed approach

tamper-evident logging (immutable, encrypted logs, verifiable timestamps), compliant retention, the ability to reconstruct a disputed decision.

The proposed control
no critical log can be modified after the fact.

Expected evidence
an observer can verify that an event was not modified.

SourcesReferences and public research

Recherche publiquePublic research sources: MITRE ATLAS 2026.07 (verified technique mapping), OWASP GenAI (catégories par abus de modèle), and the public risk-voicebot (aivansoul/risk-voicebot) template defining the 20 checkpoints. No client registry data: generic sheet, no rating, no verdict.
couche 18 · Audit Logging

Explore the 20 security layers

MITRE ATLAS 2026.07 · OWASP GenAI · risk-voicebot