The source documents
This site is written from a commissioning pack, and the pack is published in full — 11 documents — because a site whose whole thesis is "a threat model is a claim you can check" should let you check its own.
The raw markdown is the source of truth. Each reader page renders its document from the raw file in briefs/ at load time; if that fails, the page falls back to a link to the raw file.
Every file is fetchable at a stable constructed URL: /briefs/<filename>.
Read them
00 — The Brief: threat-modeling.sgit.ai
The commission, the thesis, what already exists, the honest constraints, and the build order.
Read it →01 — The Research: six white papers, one argument
The seven white papers read as one four-move argument: diagnosis, mechanism, scaling case, policy position.
Read it →02 — The Practice: seven threat models, and one that was checked
The seven real threat models, the validation pair that is this site's signature, and the method behind them.
Read it →03 — Site Architecture: threat-modeling.sgit.ai
The URL scheme, the claim-and-check spine every page follows, the data model, and the sibling deconfliction table.
Read it →04 — Disclosure Boundaries: publishing security work about a live product
The rule that governs every page on this site: publish the method always, publish findings only once closed.
Read it →05 — The Vault Argument: threat models as data with a home
Threat models as vault-native graph data, the eight frictions AppSec tools share, and what is real versus argued.
Read it →06 — Gaps and Open Questions
Six gaps and seven open questions for the founder, published unresolved rather than smoothed over.
Read it →Brief pack — README
The commissioning pack's own index: what each document is, and the one blocker (the closure pass).
Read it →Licence
The licence this pack and this site publish under.
Read it →All 11, with their raw files
Nothing here is redacted at the source-pack level
The commissioning pack is published exactly as it arrived. What it does not carry is the underlying AppSec corpus itself — the 58 review documents this pack draws from stay where they are, on the private estate, per the disclosure rule in 04__disclosure-boundaries.md: publish the method always, publish findings only once closed. The leak tripwire scans every file in this tree on every release regardless.
Licence
Every document in the pack, and every page of this site, is released under CC BY 4.0. Attribution: Dinis Cruz, via the SG/Send Librarian, with AI co-authorship credited in the papers themselves.
STRIDE, MITRE ATT&CK, CAPEC, CWE/CVE, OWASP Top 10 and ASVS are referenced and linked, never reproduced — this site publishes its own tables under those headings, and the release gate enforces the boundary on quoted text rather than the site merely stating it.