Layered threat model
A threat model that stays current: one layer for each part of the line, fed by what the other modules see, so a change in any layer re-opens the threats above it.
What it watches
- Feature and data
What the feature does, the data it touches and who is allowed to use it, as written with business and devs.
- Code
The paths that move money, check identity or parse input from outside, and the findings on them.
- Dependencies
The packages each service pulls in, their maintainers and their known issues, from the fleet and the firewall.
- Build and pipeline
Who and what can change the artefact between merge and registry.
- Registry and artefacts
Whether what is stored is signed, described by an SBOM and traceable to a build.
- Runtime and cloud
Where each version runs, what it can reach and what reaches it.
- Identity and access
Which people, services and agents hold the keys at each layer.
Seven layers, one model
Each layer lists its own threats and the data that keeps them honest. When a lower layer changes, the threats that depend on it are flagged for review.
- 7Identity & accessPeople, services and agents with keys
ThreatWho can approve a deploy? Which agent holds a cloud token?
Fed byidentity provider, AI posture
- 6Runtime & cloudWhere each version runs and what it reaches
ThreatIs the running digest the one we reviewed?
Fed byCode to Cloud
- 5Registry & artefactsSigned, described, traceable
ThreatCan someone push an image that prod will pull?
Fed byCode to Cloud
- 4Build & pipelineMerge to artefact
ThreatCan a pull request change the build itself?
Fed byPipeline auditor
- 3DependenciesPackages and their maintainers
ThreatWhat happens if a core package ships a bad version?
Fed byDeveloper fleet, package firewall
- 2CodeRisky paths and their findings
ThreatCan two requests redeem the same balance?
Fed byscans, code review
- 1Feature & dataWhat it does, for whom, with which data
ThreatWho can redeem points twice?
Fed bythreat-modeling sessions
How it connects
Every module reports to the tower. Some feed each other.
The services behind it
The module watches. These services set the station up, with your team, so there is something worth watching.
In development. Early-access teams get it first and shape what it watches.
Join early access →