threat-modeling.sgit.ai / papers / Supercharging AppSec Threat Modeling Services with GenAI and Semantic Graphs
Supercharging AppSec Threat Modeling Services with GenAI and Semantic Graphs
The commercial framing: GenAI as a force multiplier for AppSec consulting, semantic graphs as a living context layer, personalised multi-stakeholder deliverables and an implementation roadmap for a services offering.
Positioning, not method. This paper is the commercial case for a services offering built on the same graph substrate as the research above it. It is kept off this site’s main line and labelled here so it is never mistaken for one of the six research papers.
What it argues
- AI-assisted code understanding and upskilling for AppSec teams as the near-term productivity case.
- New service offerings built on the graph substrate the other six papers argue for.
- Labelled here as positioning, not method — this is the pitch deck of the set, kept separate from the research so mixing the two does not weaken either (03__site-architecture.md §6: no threat-modeling-as-a-service pitch on this site's main line).
What checks it
This paper states a mechanism and a set of consequences. The ThreatModCon 2025 vault is the working proof at the scale this and the sibling papers argue for — not a demo built to illustrate the paper, but a published vault carrying real graph data (51 nodes, 179 threats across eleven linked layers). /validated/ is the sharper instance: a threat model checked, finding by finding, against the code it describes.