threat-modeling.sgit.ai / documents

The source documents

This site is written from a commissioning pack, and the pack is published in full — 11 documents — because a site whose whole thesis is "a threat model is a claim you can check" should let you check its own.

The raw markdown is the source of truth. Each reader page renders its document from the raw file in briefs/ at load time; if that fails, the page falls back to a link to the raw file.

Every file is fetchable at a stable constructed URL: /briefs/<filename>.

Read them

commission

00 — The Brief: threat-modeling.sgit.ai

The commission, the thesis, what already exists, the honest constraints, and the build order.

Read it →
source

01 — The Research: six white papers, one argument

The seven white papers read as one four-move argument: diagnosis, mechanism, scaling case, policy position.

Read it →
source

02 — The Practice: seven threat models, and one that was checked

The seven real threat models, the validation pair that is this site's signature, and the method behind them.

Read it →
source

03 — Site Architecture: threat-modeling.sgit.ai

The URL scheme, the claim-and-check spine every page follows, the data model, and the sibling deconfliction table.

Read it →
source

04 — Disclosure Boundaries: publishing security work about a live product

The rule that governs every page on this site: publish the method always, publish findings only once closed.

Read it →
source

05 — The Vault Argument: threat models as data with a home

Threat models as vault-native graph data, the eight frictions AppSec tools share, and what is real versus argued.

Read it →
source

06 — Gaps and Open Questions

Six gaps and seven open questions for the founder, published unresolved rather than smoothed over.

Read it →
commission

Brief pack — README

The commissioning pack's own index: what each document is, and the one blocker (the closure pass).

Read it →
licence

Licence

The licence this pack and this site publish under.

Read it →

All 11, with their raw files

DocumentRaw fileKind
00 — The Brief: threat-modeling.sgit.ai00__BRIEF.mdcommission
01 — The Research: six white papers, one argument01__the-research.mdsource
02 — The Practice: seven threat models, and one that was checked02__the-practice.mdsource
03 — Site Architecture: threat-modeling.sgit.ai03__site-architecture.mdsource
04 — Disclosure Boundaries: publishing security work about a live product04__disclosure-boundaries.mdsource
05 — The Vault Argument: threat models as data with a home05__the-vault-argument.mdsource
06 — Gaps and Open Questions06__gaps-and-open-questions.mdsource
Brief pack — READMEREADME.mdcommission
LicenceLICENSE.mdlicence
Source manifest09__source-manifest.csvdata
Cataloguethreat-models__catalogue.jsondata

Nothing here is redacted at the source-pack level

The commissioning pack is published exactly as it arrived. What it does not carry is the underlying AppSec corpus itself — the 58 review documents this pack draws from stay where they are, on the private estate, per the disclosure rule in 04__disclosure-boundaries.md: publish the method always, publish findings only once closed. The leak tripwire scans every file in this tree on every release regardless.

Licence

Every document in the pack, and every page of this site, is released under CC BY 4.0. Attribution: Dinis Cruz, via the SG/Send Librarian, with AI co-authorship credited in the papers themselves.

STRIDE, MITRE ATT&CK, CAPEC, CWE/CVE, OWASP Top 10 and ASVS are referenced and linked, never reproduced — this site publishes its own tables under those headings, and the release gate enforces the boundary on quoted text rather than the site merely stating it.