threat-modeling.sgit.ai / network

The sgit.ai network

threat-modeling.sgit.ai is one site in a network of them, each built the same way — validate, auto-tag, deploy to GitHub Pages from dev — and each scoped to one subject, deliberately narrow.

The rule that keeps this clean

This site owns the act of modelling threats. If material is about the thing being modelled rather than the modelling, it belongs to a sibling.

Deconfliction, by topic

TopicOwnerThis site's part
Wardley maps as a techniquewardley-maps.sgit.aiOnly the five threat-prioritisation walkthroughs embedded in /eleven-layers/, as an application
G³, MGraph-DB, graph theorygraphs.sgit.aiOnly threat-model-shaped graphs; link out for the substrate
ISO 27001, EU AI Act, GDPRstandards.sgit.aiOnly framework-overlay-as-graph-edge; the standards text itself stays there
Risk registers, acceptancerisks.sgit.aiOnly the risk_decision field as it appears in the security schema
Vault mechanics, keyspki.sgit.ai / sgit.aiOnly what a threat model needs to say about them
NFR security posturenfrs.sgit.aiThreat modelling is the method here; NFR owns the property
Non-human identity, agent permissions as a substratesgit.ai / the parent networkOnly what one agentic threat model needs to say — see /agentic/
Open-source contribution policyopen-source.sgit.aiOnly a link, from /graph/'s contribute-back commitment

Related sites

The house pattern this site follows

Copied from pki.sgit.ai: llms.txt and /llms-full.txt, raw markdown under /documents/ with a markdown twin at every URL that has one, /admin/comms.html as the public working channel, /shipped/ as the changelog, a participant disclosure page, and the same CI pipeline — validate, auto-tag, deploy — as every other site in the network. The engineering, in full →