# Licence

## This pack

Everything in this brief pack — the seven numbered documents, `threat-models__catalogue.json`, `09__source-manifest.csv`, this file and `README.md` — is released under the **Creative Commons Attribution 4.0 International licence (CC BY 4.0)**.

    Copyright (c) 2026 Dinis Cruz
    Licensed under CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/

Attribution: **Dinis Cruz**, with AI co-authorship (Claude, Anthropic). Several of the source white papers carry their own co-authorship credit to **ChatGPT Deep Research** — preserve it wherever those papers are summarised or linked.

## The site this pack commissions

The site's own text, threat-model tables, schemas, graph data and analysis are CC BY 4.0.

## What CC BY does not cover

**Third-party frameworks.** STRIDE (Microsoft-originated), MITRE ATT&CK and CAPEC, CWE/CVE, OWASP Top 10 and ASVS, DREAD, MAESTRO: reference by name, link to the source, publish the estate's *own* tables under those headings. Do not reproduce framework text. Category names used as terms of art are fine; a copied framework is not.

**Third-party tools.** StrideGPT (`mrwadams/stride-gpt`) is another author's open-source project under its own licence. The site describes an intention to integrate and contribute back — it must not imply a partnership or endorsement that does not exist (comms Q5).

## The rules that outrank the licence

Copyright is not this site's main exposure; **disclosure is**. Two rules are build requirements, not editorial preferences:

1. **Never publish file-and-line locations of unfixed findings on a live system**, and never publish any finding's open/closed status without a date and a re-check against current code (`04__` §2, §4).
2. **Third-party findings are not the estate's to disclose.** Publish the question that was asked of a vendor, never the answer that was found.

A redacted page states that it is redacted, how many findings were held, and in which classes. A silently trimmed threat model is a false memory.
