# 06 — Gaps and Open Questions

**Version** v0.33.63 · 7 September 2026
**House rule** Published unresolved. Questions go to `/admin/comms.html`.

---

## Gaps

**G1 — The findings are six months stale.** Everything in `02__` dates from February–March 2026. Their current status is unknown to this pack. No finding may be published with an open/closed status until re-checked against current code (`04__` §4).

**G2 — The eleven-layer models were read through the published vault page, not the vault data.** The counts (51 nodes, 179 threats, 3 critical findings) and the layer list come from `sgit.ai/demos/vaults/threatmodcon-2025/index.md`. Before publishing them as generated figures, read them from the vault's own JSON — otherwise they are quoted, not computed, which is the exact distinction this network insists on.

**G3 — The ThreatModCon talk itself is not in this pack.** Slides, recording (if any), and the abstract are not on disk here. `/eleven-layers/` should carry them; the founder or the conference has them.

**G4 — No pre-2025 threat modelling material was mined.** The founder has two decades of AppSec work — OWASP-era talks, the O2 Platform, earlier writing — almost certainly including threat modelling material that predates this corpus. Same gap as the influences pack's G3, and the same fix: his own archives.

**G5 — Three threat models were catalogued but not read in depth** (token-consumption-flow, office-document-viewers-and-print, and the 16 March Simple Token model itself — read only through its validation). They are listed with dates and titles; their content needs a pass before their pages are written.

**G6 — Nothing here measures whether the method worked.** The estate can show it threat-models and validates. It cannot yet show that doing so prevented an incident. That is the honest limit of the evidence, and the site should say so rather than implying causation.

## Open questions for the founder

**Q1** — *The closure pass* (`04__` §4): which February–March findings are fixed, which are still open? This gates the whole `/practice/` section. It is the one blocker.

**Q2** — Spelling: confirm `threat-modeling.sgit.ai` with the `-modelling` variant redirecting. (Recommendation: yes — the discipline, ThreatModCon, and your own article titles all use the American spelling, even where your prose does not.)

**Q3** — The ThreatModCon 2025 talk: do you have slides/recording/abstract to publish alongside the vault?

**Q4** — The services paper (9 June): keep it on the site labelled as positioning, or hold it back until there is a service to point at? (Recommendation: keep, clearly labelled — it is part of the thinking.)

**Q5** — StrideGPT: has any contact been made with mrwadams, or is the integration still purely a stated intention? The site should not imply a partnership that doesn't exist.

**Q6** — Is there a `security.txt` / disclosure policy for the sgit.ai network yet? If not, this site's launch is the natural moment (`04__` §6).

**Q7** — The mandatory-disclosure position is a policy proposal, like the subscriptions site's legislative model. Should the two be cross-linked as a single "our regulatory positions" thread across the network?

---

This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).
