sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · threat-modeling.sgit.ai

On this page

Reading room / threat-modeling.sgit.ai · raw text · live ↗

From threat-modeling.sgit.ai, the page as fetched on 2026-09-25 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.

threat-modeling.sgit.ai — a threat model is a claim you can check

The industry's own diagnosis is that threat modeling is a fairly subjective process producing static, siloed, context-poor documents. This site publishes two things instead: models built as machine-readable graph data, and — its actual differentiator — the audit that says which parts of a threat model turned out to be wrong.

Eleven linked threat models, live at ThreatModCon 2025 · one threat model validated line-by-line against its code the next day · seven white papers · why this site is not a neutral vantage point ↗.

Source: https://threat-modeling.sgit.ai/index.html↗ · site v0.1.0 · markdown twin of the front page.


The two strongest things this site has

Everyone publishes threat models. Almost nobody publishes the audit that says which parts of theirs turned out to be wrong.

The move, in two parts

The industry's diagnosis, in the founder's words: threat modeling is "a fairly subjective process" producing "static documents" that are "siloed", "fragmented" and "context-poor". The answer here is not another methodology.

  1. Make the model machine-readable — a semantic knowledge graph, not a Word document. Threat models as graph data → ↗
  2. Make the model falsifiable — then falsify it. A threat model was written 16 March 2026; a validation pass checked every finding against the code the next day. The validation pair → ↗

The policy position that follows: threat models as mandatory disclosures ↗ — security is a market for lemons, and a published, dated, checkable threat model is the correction.

Seven white papers, one argument

Written in a burst — five of the seven inside four days at the end of May 2025 — building from a diagnosis to a mechanism to a scaling case to a policy position. All seven, in order → ↗

The honest constraints

Most of the practice material is a security review of the founder's own live product. It names unmitigated weaknesses. The rule this site publishes under: publish the method always, publish findings only once they are closed or harmless by design, hold anything still open. The disclosure boundary, in full → ↗

The graph tooling is real but young. The ThreatModCon vault is live; the continuous-modelling pipeline the papers describe is a vision with partial implementation. What is real versus argued → ↗

This site is published by the estate whose own product it threat-models — a conflict of interest worth naming rather than discovered later. The participant disclosure, in full → ↗