Participant disclosure
Read this before trusting anything else on the site. This is not a neutral third-party audit of a product — it is an estate publishing its own threat models, about its own product, under a disclosure rule it wrote for itself.
Who publishes this
threat-modeling.sgit.ai is published by the sgit.ai network, founded by Dinis Cruz, and the practice material on this site — the seven threat models, the validated pair — is a security review of the founder's own live product (SG/Send). The same person and estate whose work is being reviewed control what the review says.
Why that is not automatically disqualifying, and why it is still worth naming
Publishing your own threat models is not the same failure as, say, a vendor commissioning its own penetration test and only releasing the parts that pass. This site's rule — publish the method always, findings only once closed, everything dated — is designed to be checkable rather than merely trusted: a reader does not have to take the site's word for a finding's status, because the finding carries a date and, once closed, a version. But the incentive is real: an estate reviewing itself has more reason than a third party to under-report, to delay the closure pass, or to frame a mixed result generously. Association with your own good process is flattery, and it costs nothing to claim.
Five places the approach is weakest
The reviewer and the reviewed share an employer
No finding on this site has been produced by a party structurally independent of the product it describes. The disclosure rule constrains what gets published; it does not manufacture the independence a genuine third-party audit would have.
The closure pass is not done yet
Every finding in the practice section dates from February–March 2026; this pack is dated September 2026. Nothing may be published as open or closed until re-checked — and that re-check has not happened. Until it does, the fuller findings tables this site's own thesis calls for stay unwritten. See comms Q1 on /admin/comms.html.
"Real but young" tooling is stated by the party selling the vision
/graph/'s real-vs-argued table is this site's own accounting of its own platform's maturity. A reader should treat it as a starting point for questions, not as independently audited fact.
The vault figures are quoted, not recomputed
The eleven-layer vault's 51 nodes / 179 threats / 3 critical findings are quoted from the vault's own published summary page rather than recomputed from its underlying JSON on this site's build. Tracked as gap G2 — see the gaps document.
No incident has ever validated the method
This site can show that the estate threat-models and validates its own models. It cannot yet show that doing so prevented a real incident. That is the honest limit of the evidence, and this page says so rather than implying causation the corpus does not support.
The defence available, and its limit
Every claim on this site is checkable by somebody who does not share the estate's incentive: the method is public, the dated findings carry a status, the release gate that enforces the disclosure boundaries is itself in the public repository. That is a real defence against silent revision. It is not the same as independent verification, and this page exists so nobody mistakes one for the other.