threat-modeling.sgit.ai / papers / Threat Models as Mandatory Disclosures

Threat Models as Mandatory Disclosures

Security suffers a market-for-lemons problem — vendors know far more about their product's security than buyers do — and the proposed fix is to make threat-model publication a regulatory requirement, the way financial statements and food-ingredient labels are mandated.

Published
2025-05-29, docs.diniscruz.ai
Role
the policy position
Co-authorship
Several of these papers credit “Dinis Cruz and ChatGPT Deep Research” in their front matter — kept visible rather than smoothed away, per this site's attribution rule
Source
https://docs.diniscruz.ai/docs/2025/05/29/threat-models-as-mandatory-disclosures__a-vision-for-security-transparency.md — the paper itself, on docs.diniscruz.ai. This page summarises; it does not reproduce.

What it argues

What checks it

This paper states a mechanism and a set of consequences. The ThreatModCon 2025 vault is the working proof at the scale this and the sibling papers argue for — not a demo built to illustrate the paper, but a published vault carrying real graph data (51 nodes, 179 threats across eleven linked layers). /validated/ is the sharper instance: a threat model checked, finding by finding, against the code it describes.