Licence
This pack
Everything in this brief pack — the seven numbered documents, threat-models__catalogue.json, 09__source-manifest.csv, this file and README.md — is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).
Copyright (c) 2026 Dinis Cruz Licensed under CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/ ↗
Attribution: Dinis Cruz, with AI co-authorship (Claude, Anthropic). Several of the source white papers carry their own co-authorship credit to ChatGPT Deep Research — preserve it wherever those papers are summarised or linked.
The site this pack commissions
The site's own text, threat-model tables, schemas, graph data and analysis are CC BY 4.0.
What CC BY does not cover
Third-party frameworks. STRIDE (Microsoft-originated), MITRE ATT&CK and CAPEC, CWE/CVE, OWASP Top 10 and ASVS, DREAD, MAESTRO: reference by name, link to the source, publish the estate's own tables under those headings. Do not reproduce framework text. Category names used as terms of art are fine; a copied framework is not.
Third-party tools. StrideGPT (mrwadams/stride-gpt) is another author's open-source project under its own licence. The site describes an intention to integrate and contribute back — it must not imply a partnership or endorsement that does not exist (comms Q5).
The rules that outrank the licence
Copyright is not this site's main exposure; disclosure is. Two rules are build requirements, not editorial preferences:
- Never publish file-and-line locations of unfixed findings on a live system, and never publish any finding's open/closed status without a date and a re-check against current code (
04__§2, §4). - Third-party findings are not the estate's to disclose. Publish the question that was asked of a vendor, never the answer that was found.
A redacted page states that it is redacted, how many findings were held, and in which classes. A silently trimmed threat model is a false memory.