{
  "version": "v0.33.63",
  "generated": "2026-09-07",
  "licence": "CC BY 4.0",
  "note": "Counts verified by grep/find on 2026-09-07 against the local corpus. Vault figures are quoted from the published vault page, not computed from vault data — see 06__ G2.",
  "corpus_measurements": {
    "files_mentioning_threat_model": 269,
    "files_mentioning_threat_modeling_us": 38,
    "files_mentioning_threat_modelling_uk": 48,
    "files_mentioning_STRIDE": 27,
    "files_mentioning_attack_tree": 19,
    "appsec_role_documents": 58,
    "named_threat_model_documents": 7,
    "method": "grep -rli / find over SGraph-AI__App__Send, docs.diniscruz.ai, files.diniscruz.ai, Issues-FS__Dev, Issues-FS__Docs"
  },
  "papers": [
    {"date": "2025-05-29", "slug": "advancing-threat-modeling-with-semantic-knowledge-graphs", "role": "foundation", "claim": "Threats/assets/mitigations/incidents as graph nodes; multi-ontology overlay; MGraph-DB store", "key_content": "five named failure modes: subjectivity, siloed knowledge, no scalability, fragmented methodologies, static/context-poor"},
    {"date": "2025-05-29", "slug": "threat-models-as-mandatory-disclosures__a-vision-for-security-transparency", "role": "policy", "claim": "Security is a market for lemons; threat-model publication should be a regulatory requirement like financial statements and ingredient labels"},
    {"date": "2025-05-30", "slug": "graphs-of-graphs-of-graphs-g3-in-threat-modeling", "role": "architecture", "claim": "Multi-view/multi-graph; organic file-based evolution; ontologies as linked semantic layers"},
    {"date": "2025-05-30", "slug": "using-threat-modeling-and-semantic-graphs-to-secure-the-digital-supply-chain", "role": "domain", "claim": "Supply chain as the hardest case"},
    {"date": "2025-05-30", "slug": "scaling-supply-chain-security-using-threat-modeling-semantic-knowledge-graphs-and-maps", "role": "domain+maps", "claim": "Adds the Wardley-map visualisation layer"},
    {"date": "2025-06-02", "slug": "linking-threat-models-with-semantic-business-graphs", "role": "bridge", "claim": "Technical findings to business impact — the theory behind the multi-persona demo"},
    {"date": "2025-06-09", "slug": "supercharging-appsec-threat-modeling-services-with-genai-and-semantic-graphs", "role": "positioning", "claim": "GenAI as force multiplier for AppSec consulting", "site_label": "positioning, not method"}
  ],
  "threat_models": [
    {"n": 1, "date": "2026-02-12", "version": "v0.2.15", "path": "SGraph-AI__App__Send/team/roles/appsec/reviews/02/12/v0.2.15__threat-model__sgraph-send.md", "title": "Threat model: SGraph Send", "sections": ["system overview", "data flow diagrams", "trust boundaries", "attack surfaces", "STRIDE analysis", "zero-knowledge verification", "key threat scenarios", "recommendations by priority", "assumptions and open questions", "encryption flow verification", "frontend security review"], "notable": "STRIDE tables carry NOT MITIGATED as often as MITIGATED; server breach impact recorded as None by ZK design; 37-entry risk register"},
    {"n": 2, "date": "2026-02-25", "version": "v0.6.30", "path": "SGraph-AI__App__Send/team/humans/dinis_cruz/briefs/02/25/v0.6.30__brief__per-file-security-review-and-threat-modelling.md", "title": "Per-file security review framework and threat modelling", "notable": "bottom-up fractal method File to Method to Class to Module to Path to Endpoint to Attack Surface; parallel .security.json tree; risk_decision field"},
    {"n": 3, "date": "2026-02-26", "version": "v0.7.1", "path": "SGraph-AI__App__Send/team/humans/dinis_cruz/briefs/02/27/v0.7.1__appsec__threat-model-sg-send-skill-workflow.md", "title": "Threat model: SG/Send encrypted file transfer skill", "notable": "two-modes refusal to average symmetric vs PKI; threats T-001 to T-006 including prompt injection via file content; 8-row residual risk matrix; P0-P3 recommendations with named owners"},
    {"n": 4, "date": "2026-03-01", "version": "v0.8.4", "path": "SGraph-AI__App__Send/team/roles/appsec/reviews/03/01/v0.8.4__threat-model__token-consumption-flow.md", "title": "Threat model: token consumption flow", "status": "catalogued, not yet read in depth (06__ G5)"},
    {"n": 5, "date": "2026-03-03", "version": "v0.10.19", "path": "SGraph-AI__App__Send/team/roles/appsec/reviews/03/03/v0.10.19__threat-model__office-document-viewers-and-print.md", "title": "Threat model: office document viewers and print", "status": "catalogued, not yet read in depth (06__ G5)"},
    {"n": 6, "date": "2026-03-16", "version": "v0.16.11", "path": "SGraph-AI__App__Send/team/roles/appsec/reviews/03/16/v0.16.11__appsec-review__simple-token-threat-model.md", "title": "Simple Token threat model", "role": "the claim", "status": "read via its validation only (06__ G5)"},
    {"n": 7, "date": "2026-03-17", "version": "v0.16.14", "path": "SGraph-AI__App__Send/team/roles/appsec/reviews/03/17/v0.16.14__appsec-review__simple-token-threat-model-validation.md", "title": "Validation report: Simple Token threat model", "role": "the check", "notable": "every finding validated against backend code v0.16.14; verdicts CONFIRMED REAL / CONFIRMED SAFE / CONFIRMED MISSING / CONFIRMED CORRECT / N-A proposed-no-code"}
  ],
  "validation_verdicts": {
    "source": "v0.16.14 validation summary table",
    "confirmed_real": 2,
    "confirmed_safe": 1,
    "confirmed_missing": 2,
    "confirmed_correct": 1,
    "na_proposed_no_code": 2,
    "site_rule": "publish the N/A and missing rows; a table of only vindicated predictions is marketing"
  },
  "threatmodcon_vault": {
    "url": "https://sgit.ai/demos/vaults/threatmodcon-2025/",
    "event": "ThreatModCon 2025, Barcelona",
    "layers": ["Customer", "Business", "Application", "Component", "Package", "Class", "Method", "Source Code", "Environment", "Runtime", "Compute"],
    "nodes": 51,
    "threats": 179,
    "critical_findings": 3,
    "figures_provenance": "quoted from the published vault index page; recompute from vault JSON before publishing as generated (06__ G2)",
    "demos": ["multi-persona reframing of one SQL injection for Board / CISO / CTO / Developer", "five Wardley walkthroughs from everything-is-critical to risk-based prioritisation"],
    "engineering": "offline vault operation: d3 / three.js / tween.js inlined at pinned versions; sg.vfs.readText() for vault-relative data; network fallback reports failure rather than hiding it",
    "data_integrity_note": "two upstream JSON files repaired using only bracket adjustments and repositioning; no field edits or invented content"
  },
  "vault_argument": {
    "source_brief": "SGraph-AI__App__Send/team/humans/dinis_cruz/briefs/05/16/v0.27.45__strategy-brief__appsec-mini-tools-on-top-of-vaults.md",
    "core_insight": "every AppSec tool has a data-sharing problem; vaults solve it once for all of them",
    "pitch": "not 'we have better threat modelling than X' but 'we have a clean home for all your security artifacts, with tools that work directly on top of them'",
    "artefact_schema": ["system descriptions", "threat lists (STRIDE-categorised)", "attack trees", "DREAD scores", "mitigations", "Gherkin test cases", "evidence"],
    "first_integration_target": {"tool": "StrideGPT", "repo": "mrwadams/stride-gpt", "supports": ["STRIDE", "OWASP LLM Top 10", "MAESTRO-inspired pattern detection"], "modes": ["pure client-side for air-gapped", "ephemeral compute-backed for teams"], "caveat": "stated intention; no contact confirmed (06__ Q5)"},
    "productisation_pattern": "find a strong open-source tool, host on our infrastructure, add our UI and vault integration, contribute back"
  },
  "sgit_ai_context_2026_09_07": {
    "note": "from sgit.ai/llms.txt, fetched 2026-09-07 — vaults and features relevant to this site",
    "directly_relevant_vaults": ["threatmodcon-2025", "pentest-report", "blackhat-eu-2025 (AI vs AI)", "agentic-browser-isolation", "risk-graph-explorer", "agent-permission-games", "riskmandate-file-security", "content-transformation-proxy", "regulation-graph", "standards-atlas-gdpr", "aiuc-1-graph", "aiuc-1-conformance", "licence-to-operate"],
    "platform_features_this_site_uses": ["vault app embed in a page", "append lanes", "sub-vaults", "PKI encryption and signing", "static hosting", "window.sg bridge", "sg.vfs.readText"],
    "crypto_stack": ["AES-256-GCM", "PBKDF2-HMAC-SHA256 600k", "HKDF-SHA256", "RSA-OAEP 4096", "ECDSA P-256"],
    "network_siblings_listed": ["graphs.sgit.ai", "nhi.sgit.ai", "pki.sgit.ai", "sg-sentinel.sgit.ai"]
  }
}
