Tio av tolv fynd stängda, två reducerade med skälen utskrivna. Varje
stängning prövas av integrationssviten mot riktig Postgres — 144
kontroller, upp från 100.
T-1 Händelsenyckeln är nu (arende_id, id). Det finns inget delat
namnrum kvar att ockupera, så attacken saknar yta i stället för att
vara mildrad. Inom ett ärende bedöms en kollision på klientens
avtryck — en hash av det kanoniserade innehåll klienten skickade,
taget före serverns egna fält och före krypteringen, eftersom
varken raden eller nyttolasten går att jämföra. Identiskt innehåll
är fortfarande idempotent; samma id med annat innehåll ger 409 och
skriver ingenting alls, inte heller resten av satsen. Samma attack
en nivå upp — ärende-id är lika förutsägbart — stängs separat: ett
id som ägs av en annan organisation ger 409 i stället för att tyst
låta bli, vilket tidigare lämnade offrets ärende oskapat och varje
senare synk svarande 404.
T-2 Mätdonet slås upp i registret. Beteckning och kalibrering HÄRLEDS
därifrån och skriver över det klienten skickade. Okänt mätdon ger
400. Utgånget avvisas inte — mätningen gjordes — men registrets
datum följer med, så graderingen faller på registrets uppgift. Ett
mätvärde utan mätdon får sina påstådda uppgifter borttagna.
T-3 Reducerad, inte stängd. Personnycklarna kuverteras under en
huvudnyckel utanför databasen. En återställd dump ger nycklar som
inte öppnas — verifierat genom att starta om utan huvudnyckeln. Vad
som återstår står utskrivet: en backup tagen FÖRE en radering, plus
huvudnyckeln, återställer fortfarande uppgifterna.
Därtill: gallringen verkställs nu av ett eget jobb och grupperar på det
blindade fordonsindexet så att en delad nyckel inte gallras för tidigt
(T-4) · AI-avlästa mätvärden bär härkomst (T-5) · bcrypt kostnad 12
(T-6) · åtkomstloggen och raderingsregistret är append-only, med en
smalare regel för personnycklarna som måste kunna förstöras (T-7) ·
åtkomstloggen dokumenterad (T-8) · ett externt regelpaket utan signatur
spärrar avslut (T-9) · CORS faller inte längre öppet (T-10) · exp krävs
i token (T-11) · react-router 7 (T-12, med den kvarvarande avvikelsen
motiverad).
Den motspelande hyresgästen som revisionen efterlyste finns nu som
testform och körs i CI.
---- Vad härdningen själv avslöjade -----------------------------------
Två av rättelserna var kortvarigt fel på samma sätt som fynden, och
bägge fångades bara av att jag försökte bevisa dem:
T-7-testet var grönt mot en TOM tabell. En radnivåtrigger har inga
rader att fyra på, så delete lyckades och kontrollen mätte ingenting.
T-6-testet påstod anropet, inte kostnaden. toContain("gen_salt('bf')")
hade accepterat kostnad 6 för evigt — och gjorde det, så länge det
fanns.
Bägge är mönstret revisionen namngav: en kontroll som är riktig i sina
egna termer och oprövad vid sin gräns. Det gäller tester lika mycket som
kod.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012EQg3rJsrQ1ZNTvkzmQAtt
Semantika
Think Beyond Thought.
The world's first NeuroSemantic conversation platform. Semantika helps people explore how they create meaning, interpret their experiences, and communicate with themselves and others — through structured conversations inspired by neurosemantic principles.
Brand
- Core promise — Discover the meaning behind your thinking.
- Mission — Helping people create better meaning.
- Vision — To make NeuroSemantic thinking accessible to everyone.
Positioning. Semantika is not therapy, not self-help, and not a course. It is an intelligent reflection partner that uses neurosemantic models to help the user explore thinking patterns, communication, and perspective. Instead of quick advice, Semantika starts by helping the user explore how they interpret their situation — supporting reflection and perspective-taking, not delivering finished answers.
Honest claims. Neurosemantics and NLP are presented as inspiration and models for reflection, never as scientifically proven methods. This is enforced in the system instructions and the knowledge base; copy in the app and the stores must follow the same rule.
Tone. Never judging, dramatic, overenthusiastic, or preaching. Always calm, curious, clear, respectful, structured, thoughtful.
Design. Clinical, Scandinavian, quiet, intelligent, premium, minimal. Off-white background, near-black text, one dark blue-green accent. Generous white space. No animations, no gradients. The rule: if something can be removed without reducing user value, remove it.
Product principle. One user. One conversation. One analysis. One recommendation. That is the whole product.
System overview
apps/mobile Expo / React Native app (two views: Chat, Paywall)
services/api One Lambda backend (chat, usage, subscription verification)
infra AWS CDK stack (the entire cloud environment)
db/migrations SQL schema (two tables: users, usage)
A new developer should understand the whole system in under an hour. Every piece exists for a reason; if a feature does not make the core product better, it is not built.
Request flow
- The user lands directly in the chat — no registration before the first
question. Guests are identified by an app-generated device id
(
POST /guest/chat); dynamic conversation starters come fromGET /suggestions(both public routes). The suggestions live inservices/api/suggestions.jsonand can be updated with a deploy — no app release needed. - Requests go through API Gateway to the single Lambda; signed-in
users use
POST /chatwith a Cognito JWT (Apple / Google / email via the hosted UI). - The Lambda calls the OpenAI Responses API with the Markdown knowledge
base (
services/api/knowledge/) as system instructions: neurosemantic models, communication models, the conversation guide, reflection exercises, and a question library. V1 invests in prompt design quality, not infrastructure complexity. The model returns structured output: a reply plus ananalysis_readyflag. - Sign-in happens at the paywall, since a purchase must attach to an account. Usage counters live in PostgreSQL (Aurora Serverless v2).
The intelligent paywall
Monetization philosophy. The goal is not to interrupt the conversation — the goal is to build trust. The free experience should make the user feel understood, respected, and curious to continue; only when the conversation has reached a meaningful point is Premium introduced. The rule given to the model, verbatim: "Never manufacture suspense. Create genuine curiosity by helping the user reach a meaningful insight, then offer a deeper level of analysis in Premium."
The paywall is not a hardcoded message count. Free conversations run in
discovery mode: the model asks relevant follow-up questions, names
patterns, shows understanding, and helps the user reach a meaningful
insight of their own. When the conversation has reached that point and the
natural next step is a complete analysis, a structured framework, a
personalised strategy, practical exercises, or a step-by-step action plan,
the model pauses immediately before delivering it — never mid-sentence,
never in the middle of an explanation — signals analysis_ready, and
writes a calm transition: "I think I understand the core pattern behind
what you've described. There are a few recurring themes that stand out, and
I have a structured way of working through them with you. Unlock Premium to
continue with the full analysis and your personalised action plan."
Product feeling. Every interaction should leave the user thinking "this understands me". Every Premium conversion should feel like "I genuinely want to continue this conversation" — never "they stopped me just to make me pay". Manufactured urgency, emotional pressure and fake readiness are explicitly forbidden in the instructions.
On unlock, the app resends the transcript; premium mode then delivers the full analysis, recommended strategies and concrete exercises immediately, and the dialogue continues without restriction.
A generous MESSAGE_CAP (default 200 per 30 days) exists purely as an
abuse backstop for the free tier — it is not the paywall.
Conversations are never stored server-side; the client holds them in memory
and sends the running transcript with each request. The database stores the
absolute minimum: users (id, email, auth_provider, subscription,
created_at) and usage (messages_used, last_reset). No profiling, no
training on user data. Error logging is anonymized (no message content).
Payments
Subscription logic is shared (services/api/src/subscription/); the payment
provider differs per platform behind one PaymentProvider interface:
- iOS — In-App Purchase; the backend verifies the app receipt with Apple.
- Android — Google Play Billing; the backend verifies the purchase token with the Play Developer API.
- Web (future) — a Stripe adapter slots into the same interface.
Plans: Monthly and Yearly. Nothing else.
Pricing. $5.99/month, $49.99/year (≈30 % below the monthly rate).
Premium includes unlimited conversations, unlimited analyses, personalised
guidance, and future feature updates. Prices are configured in App Store
Connect / Play Console on the products semantika_monthly and
semantika_yearly; the paywall fetches localized prices from the store and
falls back to these defaults until the store answers.
Getting started
npm install # installs all workspaces
npm run lint
npm run typecheck
npm test
Mobile app
cd apps/mobile
npm start # Expo dev server
Fill in extra in app.json (API URL, Cognito domain and client id) from
the CDK stack outputs. In-app purchases require a development build
(expo run:ios / expo run:android), not Expo Go.
Backend + infrastructure
cd infra
npx cdk deploy
After the first deploy:
- Put values into the
semantika/appsecret in Secrets Manager:OPENAI_API_KEY,APPLE_SHARED_SECRET,GOOGLE_SERVICE_ACCOUNT_JSON. - Run
db/migrations/001_init.sqlagainst the cluster (credentials are in the RDS-managed secret). - Optional: enable Apple/Google sign-in by passing CDK context
(
googleClientId,googleClientSecret,appleTeamId,appleKeyId,applePrivateKeySecretName). Email sign-in works out of the box.
CI/CD
GitHub Actions: ci.yml lints, type-checks and tests every PR;
deploy.yml deploys the CDK stack on every push to main (set the
AWS_DEPLOY_ROLE_ARN secret for OIDC). Store builds ship via EAS
(eas build, profiles in apps/mobile/eas.json).
The full path to the closed beta — AWS, stores, builds, testers — is in LAUNCH.md.
Security
- All traffic over HTTPS. Account routes require a Cognito JWT; the two
public routes (
/suggestions,/guest/chat) carry no account data and are bounded by the free-tier message cap. - Secrets live in AWS Secrets Manager only — no API keys in the client.
- The Lambda runs in private subnets; the database is not publicly reachable.
Product philosophy
People grow when they become more aware of how they create meaning, interpret their experiences, and shape their decisions. Some users come seeking change, structure or guidance; others are simply curious and want to develop. Semantika never assumes the user is struggling — it starts from the assumption that they want to grow, and meets them where they are.
Human Experience Doctrine. Every user should feel seen, respected, understood, capable, and hopeful. The system must never create dependency or give the impression that it alone has the answers; its purpose is to strengthen the user's own ability to reflect and decide.
Conversation philosophy. Every conversation moves through four steps: acknowledge (show the meaning was understood, not just the words), explore (discover new perspectives together — no interrogating, no over-analyzing), lift (name resources and strengths with concrete, credible praise — never generic compliments), and challenge (leave the user with at least one new thought, question, model, or direction).
Personality. A very experienced coach, a calm mentor, a skilled teacher, a wise conversation partner — never a therapist, a salesperson, a preacher, or a guru. Warmth, curiosity and structure over stage energy.
Educational philosophy. Semantika does not just answer — it teaches the user how to reflect: to think more clearly, communicate better, understand their own reactions, and ask better questions. Success means the user gradually needs the tool less, because they build skills of their own.
Every free user should leave the app feeling that the system understood their situation, that a concrete analysis is ready, and that the next step is available in Premium — never that they were held back by an artificial interruption.
Every new feature must justify itself. The allowed AWS surface is API Gateway, Lambda, Cognito, S3, Secrets Manager and CloudWatch — and V1 does not even need S3. No Redis, no Kubernetes, no Kafka, no Elasticsearch, no queues, no microservices. One backend. Maximal simplicity.
Definition of Done
Version 1 is done when a user can:
- Open the app.
- Start a conversation immediately.
- Feel seen and understood.
- Receive a number of well-considered follow-up questions.
- Reach a natural premium boundary.
- Buy Premium.
- Continue the conversation.
If a feature does not help the user reflect better, it is not built. Version 1 must be small, fast, stable, and easy to maintain.
Roadmap
Build a strong core product first; only then build around it.
- Version 1 (this repo) — Person ↔ Semantika. Nothing else.
- Version 2 (not now) — journal, saved insights, community, certified coaches, courses, voice conversations. None of these are built in V1.
Next step: a closed beta. Put V1 in the hands of 20–50 test users
before adding anything. The minimal data model already answers several of
the key questions — how many come back (usage.last_reset vs activity),
how deep dialogues go (messages_used), and when users upgrade
(subscription transitions). Which starter questions create the most value
requires asking testers directly, since conversations are never stored.
Anything beyond that must justify itself against the privacy rule.