threat-modeling.sgit.ai / papers / Supercharging AppSec Threat Modeling Services with GenAI and Semantic Graphs

Supercharging AppSec Threat Modeling Services with GenAI and Semantic Graphs

The commercial framing: GenAI as a force multiplier for AppSec consulting, semantic graphs as a living context layer, personalised multi-stakeholder deliverables and an implementation roadmap for a services offering.

Published
2025-06-09, docs.diniscruz.ai
Role
positioning, not method
Co-authorship
Several of these papers credit “Dinis Cruz and ChatGPT Deep Research” in their front matter — kept visible rather than smoothed away, per this site's attribution rule
Source
https://docs.diniscruz.ai/docs/2025/06/09/supercharging-appsec-threat-modeling-services-with-genai-and-semantic-graphs.md — the paper itself, on docs.diniscruz.ai. This page summarises; it does not reproduce.
Positioning, not method. This paper is the commercial case for a services offering built on the same graph substrate as the research above it. It is kept off this site’s main line and labelled here so it is never mistaken for one of the six research papers.

What it argues

What checks it

This paper states a mechanism and a set of consequences. The ThreatModCon 2025 vault is the working proof at the scale this and the sibling papers argue for — not a demo built to illustrate the paper, but a published vault carrying real graph data (51 nodes, 179 threats across eleven linked layers). /validated/ is the sharper instance: a threat model checked, finding by finding, against the code it describes.