Threat Modeling
Threat-model records support systems, assets, trust boundaries, threats, mitigations, owners, and review status. STRIDE is the default method, with research cases and findings linked as evidence.
secopsai enterprise workflow threat-model --input threat-model.json --json
Model-generated suggestions remain proposals. A reviewer must accept threats, mitigations, and residual-risk decisions.