But on the other hand, to the extent that you're going beyond aggregating and curating public data, you are adding risk. And on both your web site and in other public discussions, you seem to acknowledge that there's something there to talk about (why have a security page otherwise?), but there's been a continual marked reluctance to get into specifics about even the nature of what data you're collecting, let alone how you're managing it.
What's more worrisome, this all comes after the assertion that even though the "user functionality" code is slipshod, you're still confident that "anything to do with security is not compromised." Security doesn't work like that. If you're unfortunate enough to have a buffer overflow on the machine running your stuff, it's compromised. Even if that's only in the "user functionality" code. Even if it isn't your code at all, but some other service that you weren't using, but forgot to turn off or firewall away.
You might also want to try a bit harder to see things from the point of view of your critics. One of the things they're thinking about is the Haystack anti-censorship project, which attracted enormous hype in the technical and mainstream press, but collapsed after a much-delayed security audit found the code badly wanting. I now find a collection of laments about it[1] as the top result in a Google search for "iran social media security fiasco". That's what your critics are worried about. And I'm not sure it's entirely fair on your part to ask for a more specific run-down of technical risks than that when outsiders haven't yet seen, in specific technical detail, a full run-down from your side of what the system is supposed to do in the first place.
[1] The actual page: http://webography.wordpress.com/2010/09/24/recent-resources-...
EDIT [in response to [name redacted]]: I understand that you guys are under time constraints, but you and Gausie did find time to write over 1500 words of comments between you on this HN page alone. If you'd written half that much text describing your security model in a concrete, specific, technical way we'd be having a much more productive conversation.