threat-modeling.sgit.ai / network
The sgit.ai network
threat-modeling.sgit.ai is one site in a network of them, each built the same way — validate, auto-tag, deploy to GitHub Pages from dev — and each scoped to one subject, deliberately narrow.
The rule that keeps this clean
This site owns the act of modelling threats. If material is about the thing being modelled rather than the modelling, it belongs to a sibling.
Deconfliction, by topic
| Topic | Owner | This site's part |
|---|---|---|
| Wardley maps as a technique | wardley-maps.sgit.ai | Only the five threat-prioritisation walkthroughs embedded in /eleven-layers/, as an application |
| G³, MGraph-DB, graph theory | graphs.sgit.ai | Only threat-model-shaped graphs; link out for the substrate |
| ISO 27001, EU AI Act, GDPR | standards.sgit.ai | Only framework-overlay-as-graph-edge; the standards text itself stays there |
| Risk registers, acceptance | risks.sgit.ai | Only the risk_decision field as it appears in the security schema |
| Vault mechanics, keys | pki.sgit.ai / sgit.ai | Only what a threat model needs to say about them |
| NFR security posture | nfrs.sgit.ai | Threat modelling is the method here; NFR owns the property |
| Non-human identity, agent permissions as a substrate | sgit.ai / the parent network | Only what one agentic threat model needs to say — see /agentic/ |
| Open-source contribution policy | open-source.sgit.ai | Only a link, from /graph/'s contribute-back commitment |
Related sites
- sgit.ai — the parent project and the network index
- wardley-maps.sgit.ai
- graphs.sgit.ai
- standards.sgit.ai
- risks.sgit.ai
- pki.sgit.ai
The house pattern this site follows
Copied from pki.sgit.ai: llms.txt and /llms-full.txt, raw markdown under /documents/ with a markdown twin at every URL that has one, /admin/comms.html as the public working channel, /shipped/ as the changelog, a participant disclosure page, and the same CI pipeline — validate, auto-tag, deploy — as every other site in the network. The engineering, in full →